Podcasts about MDR

  • 862PODCASTS
  • 23,082EPISODES
  • 18mAVG DURATION
  • 10+DAILY NEW EPISODES
  • Aug 13, 2026LATEST

POPULARITY

20192020202120222023202420252026

Categories



Best podcasts about MDR

Show all podcasts related to mdr

Latest podcast episodes about MDR

Wissen
Kann die AfD den MDR abschaffen?

Wissen

Play Episode Listen Later Aug 13, 2026 34:38 Transcription Available


Die AfD will im Fall einer Regierungsübernahme den MDR-Staatsvertrag kündigen. Was würde eine solche Kündigung für den MDR und die Menschen in Sachsen-Anhalt bedeuten? In dieser Podcast-Episode blicken wir ausführlich auf die möglichen Folgen. (00:00:00) Begrüßung (00:02:30) Bedrohung des MDR (00:13:36) Szenarien & Gegenwehr (00:25:53) Ausblick (00:30:48) Lieblingsort und Verabschiedung Sachsen-Anhalt ist nur sehr selten Thema in deutschlandweiten Medien, und auch in Sachsen-Anhalt selbst gibt es nur sehr wenige Medien. Große Aufmerksamkeit bekommt das Bundesland häufig nur wie jetzt vor Landtagswahlen oder bei Katastrophen. Im Podcast werden wir mindestens bis Ende Dezember 2027 dazwischengehen und dazwischenfragen. Wir schauen im Podcast auf die verschiedenen Regionen Altmark, Anhalt-Dessau-Wittenberg, Halle, Harz, Magdeburg, Mansfelder Land und Saale-Unstrut. Zusätzlich gibt es einen Newsletter. Damit könnt ihr jeden Donnerstag direkt in eurem Mailfach Geschichten aus und für Sachsen-Anhalt lesen. Im Newsletter beleuchten wir immer auch weitere Themen und Regionen. Ihr findet dort beispielsweise überraschende Zahlen und Fakten, Geschichten aus den Regionen Sachsen-Anhalts und Tipps von anderen Leserinnen und Lesern. Alle Infos unter https://detektor.fm/dazwischen Der Newsletter: https://detektor.fm/unsere-newsletter/dazwischen Unser WhatsApp-Kanal: https://www.whatsapp.com/channel/0029Vb8Caqp89iniJZy0Dj1Z Der Podcast DAZWISCHEN entsteht im Rahmen eines Kooperationsprojekts mit der Media Forward Fund gGmbH. Die redaktionelle Verantwortung liegt bei der BEBE Medien GmbH. ➡️ Artikel zum Nachlesen: https://detektor.fm/wissen/dazwischen-afd-plaene-zur-kuendigung-des-mdr-staatsvertrags-in-sachsen-anhalt

Podcasts – detektor.fm
DAZWISCHEN Der Sachsen-Anhalt-Podcast | Kann die AfD den MDR abschaffen?

Podcasts – detektor.fm

Play Episode Listen Later Aug 13, 2026 34:38 Transcription Available


Die AfD will im Fall einer Regierungsübernahme den MDR-Staatsvertrag kündigen. Was würde eine solche Kündigung für den MDR und die Menschen in Sachsen-Anhalt bedeuten? In dieser Podcast-Episode blicken wir ausführlich auf die möglichen Folgen. (00:00:00) Begrüßung (00:02:30) Bedrohung des MDR (00:13:36) Szenarien & Gegenwehr (00:25:53) Ausblick (00:30:48) Lieblingsort und Verabschiedung Sachsen-Anhalt ist nur sehr selten Thema in deutschlandweiten Medien, und auch in Sachsen-Anhalt selbst gibt es nur sehr wenige Medien. Große Aufmerksamkeit bekommt das Bundesland häufig nur wie jetzt vor Landtagswahlen oder bei Katastrophen. Im Podcast werden wir mindestens bis Ende Dezember 2027 dazwischengehen und dazwischenfragen. Wir schauen im Podcast auf die verschiedenen Regionen Altmark, Anhalt-Dessau-Wittenberg, Halle, Harz, Magdeburg, Mansfelder Land und Saale-Unstrut. Zusätzlich gibt es einen Newsletter. Damit könnt ihr jeden Donnerstag direkt in eurem Mailfach Geschichten aus und für Sachsen-Anhalt lesen. Im Newsletter beleuchten wir immer auch weitere Themen und Regionen. Ihr findet dort beispielsweise überraschende Zahlen und Fakten, Geschichten aus den Regionen Sachsen-Anhalts und Tipps von anderen Leserinnen und Lesern. Alle Infos unter https://detektor.fm/dazwischen Der Newsletter: https://detektor.fm/unsere-newsletter/dazwischen Unser WhatsApp-Kanal: https://www.whatsapp.com/channel/0029Vb8Caqp89iniJZy0Dj1Z Der Podcast DAZWISCHEN entsteht im Rahmen eines Kooperationsprojekts mit der Media Forward Fund gGmbH. Die redaktionelle Verantwortung liegt bei der BEBE Medien GmbH. ➡️ Artikel zum Nachlesen: https://detektor.fm/wissen/dazwischen-afd-plaene-zur-kuendigung-des-mdr-staatsvertrags-in-sachsen-anhalt

Das Beste vom Morgen von MDR AKTUELL
Neue Zeitzeugen-App zum Mauerbau vor 65 Jahren

Das Beste vom Morgen von MDR AKTUELL

Play Episode Listen Later Aug 13, 2026 3:58


Zum Jahrestag des Mauerbaus haben MDR und WDR ein neues Projekt gestartet, um Alltagsgeschichte ins Klassenzimmer zu bringen. Daran mitgewirkt haben Schülerinnen und Schüler aus Halle und Köln.

ChannelBuzz.ca
Logging in, not breaking in: Blackpoint Cyber’s Wil Santiago on the 2026 threat landscape

ChannelBuzz.ca

Play Episode Listen Later Aug 13, 2026 30:07


Wil Santiago, Wil Santiago, chief security and trust officer at Blackpoint Cyber Wil Santiago, chief security and trust officer at Blackpoint Cyber, joins In The Channel to discuss the findings of the company’s 2026 Annual Threat Report – research grounded in thousands of real incidents investigated by Blackpoint’s security operations centre, not surveys. The headline finding: attackers are no longer trying to break in. They’re logging in. Using stolen credentials and commodity remote management tools, threat actors are walking through the front door, hiding in plain sight, and operating with system-level privileges – sometimes for days before anyone notices. Santiago walks through the key trends the SOC identified across 2025: ClickFix and fake CAPTCHA campaigns accounted for more than half of all identifiable incidents, with attackers abusing trusted infrastructure including Azure Blob storage and Cloudflare to deliver payloads. RMM abuse showed up in roughly 30 per cent of triaged incidents – threat actors installing their own version of the same tools MSPs use legitimately, then living off the land with god-mode access. And Adversary-in-the-Middle attacks are now routinely hijacking authenticated sessions even when MFA is in place, by abusing OAuth token handling. The conversation also covers Blackpoint’s detection philosophy: behavioral context over malware signatures. Understanding what normal looks like in an environment – who uses what tool, at what time, from where – is what allows the SOC to catch attackers before they act. It’s a philosophy that is producing results: Blackpoint disrupted 56 per cent of incidents before a payload was ever deployed. Santiago’s closing recommendation for MSPs is straightforward: start with an RMM audit. Know every remote management tool deployed across every endpoint and server you manage. You cannot protect what you don’t know exists. The 2026 Annual Threat Report is available for download on the Blackpoint Cyber website. Read Full Transcript Robert Dutt: Hello and welcome to In The Channel from ChannelBuzz.ca, bringing news and information to the Canadian IT channel community for the last 16 years. I’m Robert Dutt, editor of ChannelBuzz.ca and your host for the show. Wil Santiago is Chief Security and Trust Officer at Blackpoint Cyber, an MDR provider whose SOC monitors and responds to threats in real time across a large base of MSPs and their clients. And unlike a lot of threat research that’s survey-based or derived from external reporting, what Blackpoint publishes comes from live incident data, thousands of actual threat responses they’ve worked through in the SOC. Their 2026 annual threat report has a thesis that cuts right through it. Attackers are no longer trying to break in, they’re logging in, using stolen credentials and legitimate IT tools, the same RMMs, the same cloud platforms that MSPs rely on every day, to walk through the front door, hide in plain sight, and work their way towards payday. It’s a theme we’ve been tracking at ChannelBuzz.ca. If you caught our conversation with Tony Anscombe from ESET, that one dug into the mechanics of how MSP tools are being weaponized against the very clients they’re supposed to protect. This conversation is the data layer behind that story, and the detection philosophy that Wil and the Blackpoint team have built to counter it. Their SOC is disrupting 56% of incidents before a payload even deploys. We talk about how. Let’s get right into it. My chat with Wil Santiago. Wil, thanks for taking the time, I appreciate it. Wil Santiago: Thank you, Robert. Robert Dutt: For people who know Blackpoint primarily as an MDR provider, but maybe haven’t dug into the research side, can you give us a quick sense of what your SOC is actually seeing day to day? When you say this report is based on thousands of real incidents, what does that mean in practical terms, in terms of how you gathered this data? Wil Santiago: That’s a great question, Robert. It really starts at the core of what we focus on at Blackpoint Cyber. In 2025, we focused a lot of our detection efforts in the cloud endpoints, but what we realized is that at the core, at that identity layer, that’s the most important thing. But what we’re protecting at Blackpoint is the identity. What we observed in 2025 is this interesting shift where, yes, there’s vulnerabilities, there will continue to be vulnerabilities. However, threat actors don’t necessarily need to weaponize those vulnerabilities to gain access into an environment. They’re not really targeting customers or companies with any specific new zero-day technology or exploits that are novel. They’re just logging in using stolen passwords. We’re still at that pivotal point, but we’re still talking about the same things we’ve been talking about, password reuse, making sure you’re protecting yourself from phishing emails, so on and so forth. But the reality is that threat actors are getting in. They’re stealing credentials and they’re using legitimate tools to just log in, walking through the front door. Robert Dutt: Yeah, the headline from the report was very catchy with the attackers are no longer trying to break in. They’re just logging in, as you say. And that framing echoes what we’ve seen in other reports elsewhere. People are calling 2025 the year of the abuse of trust in terms of security trends, but your numbers are operational and not survey-based. I’m curious what trusted compromise looks like from where you sit. Is there really a shift away from what you were seeing a couple of years ago or three years ago, or has this always been the playbook and we’re only now measuring it properly? Wil Santiago: Yeah, so if I compare back to, let’s say, 2022, I think we at Blackpoint would still see a trend, the threat actors gaining access into an environment, usually using some type of exploit at that time. You can point to a number of Microsoft Exchange exploits that happened during that time. The Hafnium group was doing a lot of Exchange exploits. The reality is there came a certain time where we were detecting Cobalt Strike, a malware commodity tool, every single day in Blackpoint Cyber’s SOC. And then eventually it became once a week, and then it became once a month. So then we started to think, well, what’s happening with the shift of tactics with the threat actors? And what we found is instead of installing Cobalt Strike, they started to install legitimate IT tools. And that’s the trust component. When they’re installing tools that you use internally, they now can abuse those tools the same way that you use those legitimately. And so we have these threat actors that not only are abusing legitimate tools, but like I said, they’re abusing legitimate identities. So when you have what I call the keys to the kingdom, the passwords, I am you. I am now Robert, for all intents and purposes for this sort of webinar. I think the interesting part that we’ve seen at Blackpoint is that threat actors have really, really focused on leave-behinds. And those leave-behinds are commodity remote management tools. Why do they do that? Because EDRs don’t know how to detect them as malicious, right? These are legitimate IT tools that are being used to service MSPs and their customers. And a threat actor just installs their version of the same exact tool that you’re using legitimately. Right? And so the trust component is you go to review your assets and you see ScreenConnect installed in your environments because you use ScreenConnect, right? But then when you start taking a closer look, you start to realize, wait a second, there’s four different ScreenConnect IDs on this one machine. Now we have a more of a problem, right? And so the attack is a little bit of an invisible signature detection because it’s an authorized tool, right? And so we really have to get to this layer of identifying threat actor activity with behavior context. If you’re an AnyDesk shop, then why do you have TeamViewer installed on your file server that’s publicly facing, right? Let’s start to ask those questions and dig into that a little bit. Robert Dutt: Your SOC found that fake CAPTCHA and ClickFix campaigns accounted for, I think it was 50-odd percent of identifiable incidents. That’s a majority of attacks being driven by a technique that essentially requires the victim to step on the link to execute it themselves. Why is that scaling so fast right now? And especially for an MSP who tends to think, you know, my technicians are too smart to do that. What’s kind of the honest answer for what they need to be looking for and protecting against? Wil Santiago: Yeah. And, you know, ClickFix is such an easy attack when you really get into the root of what it does. But it starts with social engineering. You’re enticing someone, again, just like with phishing, to visit something that you’re going to tell them to do an action. And most of the time, they’re going to do that action. Now, why this is so effective is we’re seeing techniques that really enable the threat actor to deliver the payload. And how do they do that? Search engine optimization, right? These SEO links at the top, when you go look for an OBS installer, because you need your camera to look well, or you get a Google sponsor result. Threat actors are just buying those sponsored results and delivering their payloads on there. You click on it thinking you’re going to download OBS, and then it tells you, hey, wait a second, you have to make sure that you are human. Verify that we’re used to verifying we’re humans to download something. So we go and we click it. But then it says, hey, open up your Windows Run command and maybe run this command on us, on your computer for us. And what happens? Threat actors go and they put the commands on a website. They have this watering hole spread out all throughout infrastructure that’s globally distributed. Google, Microsoft, all these sort of cloud infrastructure hosting providers that exist. Threat actors use those. So when you’re looking at your firewall logs and you’re seeing your internal team going to Microsoft.com, hey, it’s Microsoft, right? But the reality is, it’s likely an Azure Blob site that’s just being hosted on Microsoft, that is a threat actor that’s actually hosting it. And so they’re abusing that trust function to say, hey, you need this OBS installer. You Googled it. I didn’t tell you to go Google that. You were the one that did that. And then they found my link, which I posted a malicious payload there. And so again, that abuse factor is all the things we’ve taught our employees, our customers, our MSPs to do, right? Go to Google, make sure you identify the link. Make sure you look for Microsoft. Make sure you see the end of a URL or domain. Validate that. Well, the adversary goes, okay, they want to play that game. I’m just going to host this on Cloudflare. And now we’re back to this gate where now someone clicks on something. Well, what’s this Cloudflare? That’s a legitimate service. I know that to be true, right? It’s very true. The reality is the infrastructure is very, very easy to set up. And it doesn’t require a lot of action. It just requires someone to take a command and put it on their machine. And all the background work happens in the background, right? And so beyond that, we used to see a lot of threat actors use this sort of technique to download malware onto machines. But again, going back to what I mentioned about RMMs, now they’re just downloading an RMM. And that just looks like a legitimate process to an EDR. Robert Dutt: Right. So for an MSP, especially when training or making sure their technicians are aware, is it just as simple as making sure they’re aware of this threat landscape and this wrinkle in it? Or is there something more that’s sort of the advice there on how to protect yourself as best you can? Wil Santiago: That’s a great question. And really, you know, I would say any MSP watching this show, starting today or tomorrow, the first thing that I always tell people, audit your RMM inventory. Asset inventory is the number one thing that customers should be doing, right? You cannot protect what you don’t know exists. And so every single remote management tool that’s deployed across every endpoint you manage, every server you manage, you need to audit those, right? Like you’re giving direct access to a system. And most of the time, those RMMs run in the system context, which means they have the permissions and privileges of any admin, right? And now you have this adversary that has a foothold. They can deploy tools using admin privileges and permissions. So you have to audit your RMM inventory, right? Making sure that you understand what’s happening across those production servers. And forcing MFA, that’s a big one. We see a lot of incidents that source from RMM abuse because they log into the MSP’s RMM console, the cloud-based consoles. Some of those don’t have MFA involved. Again, keys to the kingdom, MFA everywhere, that needs to be a reality. Then we need to start moving into what I call more resilient engineering, right? Conditional access policies, preventing individuals from logging in from untrusted sources, locations, right? There’s ways that you can lock down access to an RMM and assume a threat actor is able to steal credentials because they maybe installed an info stealer on a user’s machine, stole their browser credentials. They reuse the same credentials for Gmail that they do for their corporate environment. Well, now a threat actor just perusing finds their credentials and says, “Oh, I’ve got IT Glue permissions now. I’m going to go log into this and restore all these configs in IT Glue or whatever tools out there.” Well, now the threat actor has access to that. And so that’s how they’re pivoting across these environments. They’re going from cloud to on-prem, on-prem to cloud. One of the things that we caught at Blackpoint recently, and this was a really cool response, but the threat actor compromised the cloud environment first. They then took that cloud access, deployed an RMM using Intune to the devices, and then they used that on-prem access to go to those machines and do their own work directly from that console. I called it overkill. They didn’t have to do that because they had the cloud environment. But because they did that, that sort of prompted this investigation for this MSP to approach us and say, “Hey, we believe something is happening. We investigated and quickly saw the Intune process was the responsible process for deploying some of this malware. So we told them, “Hey, deploy our cloud response suite. We want to understand what’s happening in your cloud.” And sure enough, seven global admins were compromised. So again, limiting scope is important here, right? Least privilege. Why do we have so many people with admin privileges and permissions? I think there’s 192 admin roles or something like that in Microsoft, but we default to just, you get global admin, you get all the permissions. And so now an adversary compromises a Microsoft 365 tenant. Well, now they have the permissions of a global admin. And unfortunately for us, when we shifted from the on-prem strategy to the cloud strategy, we just started pushing everything in the cloud and we say, “Oh, it’s fine. It’s in SharePoint.” We didn’t realize though that that’s only being protected by a password and an MFA token, both of which can be stolen, right? So the protection is not really there. That’s why we have to move to that resilient engineering. And so it’s moving from that reactive alerting to that posture alerting, right? Why is someone trying to log in from France? We have nobody in France. Robert Dutt: So your report showed almost a third of triaged incidents involved RMM abuse. And that’s something, that kind of trend line is something that we’ve seen in other reports. You know, one of your peers is talking about a 200 plus percent spike in abuse of RMM in attacks. I’m curious, especially since you’re sitting in the SOC there, what does RMM based intrusion actually look like in the SOC here? You know, I’m guessing curious, is there a moment where it’s genuinely hard to tell, you know, is this actually a tech doing a routine task or is this an attacker? And if so, what kind of breaks the tie and causes you to go, “No, no, that’s not right.” Wil Santiago: Yeah. Well, there’s kind of two ways to look at it, right? We have threat actors that are compromising MSP RMM tools. These are tools that are owned, managed by the MSP. They’re usually protected with some cloud login, whether they self-host it or they have the vendor host it for them. Threat actors can log into those systems with a password and a username, right? So we see a lot of brute forcing of those systems, especially if they’re self-hosted systems, they usually don’t have the protections of the vendors. They don’t put a WAF in front of them. And so they’ll try to brute force them and just log in, right? Those are few and far between, to be quite honest. We don’t see those as often, but what we do see often is, again, they gain access into an environment, usually by compromising a VPN. Now they’re on the network. Now they can move throughout that network as they’re on the VPN, and they’ll usually find a foothold. And if they have a credential like a local admin, they’ll take that one foothold and then they’ll distribute their RMM across that entire fleet of the network with one command from that foothold. So for us, when we’re looking at RMM deployments, MSPs deploy RMMs in a certain manner and format. They’re not deploying an RMM at two o’clock in the morning on a Saturday when they’re a US-based company. And oh, by the way, they just logged in from a Chinese-based IP, right? So again, there’s indicators that are very clear cut of like, okay, this deployment of RMM tools absolutely malicious. Most of those cases come to the case of, you know, we have application control within Blackpoint that allows us to alert when someone is installing a new application that’s unauthorized. And so what we tell our MSPs to do is, hey, set up your policies that if you’re a Ninja RMM shop, you cannot have any other installations of any other RMM. ScreenConnect is not going to be involved. And so that allows us and affords us the ability to do is, when we get that alert that says someone’s attempting to install a ScreenConnect, we can go back and sort of recreate the path of how do they get here. And what that allows us to really get into is, again, that response, right? And that response is preventing the installation of the RMM, eradicating the threat actor by isolating the machine, making sure you remove their footholds, getting those SSL VPNs off of the public facing internet, and having that exposure management reduced, right? And so when we look at RMM abuse in practice, once they get that RMM installed, again, they’re living off the land with system privileges. System privileges is something that most people tend to understand, but it’s just keys to the kingdom. You are God mode at that point. You can do whatever you feel to deploy and ultimately spread your access with that level of access, right? And so they’ll use it for backdoors. And oftentimes, they may compromise the environment and say, “You know what? I’m busy.” We’ve actually seen this over the holidays where they go take their breaks. Just like everyone else does. It’s Christmas. I’ve done a lot of hacking. So they leave their leave-behind tools and they come back. That’s their access factor. Again, it’s one of those things where they’re hiding in plain sight. Robert Dutt: You touched on MFA a little while ago and the report flagged the use of adversary-in-the-middle attacks. AiTM attacks that let threat actors hijack authenticated sessions, even when the MFA is there. So I guess what’s the message to MSPs who are thinking, “All right, if we just get MFA everywhere, we’re good, we’re covered.” Wil Santiago: Token protection, right? MFA is great. You have to have it. But understand that there’s flaws in the way that MFA communicates to servers. And so the whole way that an adversary-in-the-middle attack works is by abusing OAuth. And OAuth is a standard protocol of just making sure that we understand how systems should communicate for authentication. And what’s really nice about that is we can take that offensive research and then make defensive practices towards that. And so token protection is really huge there. There are a lot of built-in protections in Microsoft that allow you to invalidate session tokens after a certain period of time. Every hour you could refresh these tokens. You now, again, when you get to this resilient engineering, you start to push the adversary to be a little bit more aggressive. And that’s your detection mechanism. When you allow an adversary to move unfettered throughout a network, they’re going to move unfettered throughout a network. But the moment that you give them that sort of, “Eh, stop here. Let me see your ID.” Then they start to get a little uneasy. They’re like, “Wait a second. I don’t know how to move anymore.” And so specifically in MFA, when we talk about session hijacking and session tokens, the token protection aspect is really important because that’s a conditional access policy that you can implement. And most people do not implement those conditional access policies. Now, there’s a slew of them that work in conjunction with each other. But the idea here is your tokens will likely be compromised at some point. If you are duped into clicking one of these phishing links, it’s very easy to steal a session token. So we have to move past that. Now that we know that’s going to happen, how do we prevent the adversary from actually using those session tokens successfully? And that’s where invalidating the sessions comes in, having the session protection, conditional access policies, protected devices, things of that sort. That prevents them from being able to use those session tokens. Robert Dutt: A stat that I keep looking at in the report was that you guys managed to disrupt in the SOC 55, 56 percent of incidents before a payload was deployed. It’s a real number. That’s pretty significant. I guess what is disrupted before the payload hits mean operationally? And what does it tell us about where the detection opportunity actually lives? Because it sounds like the window isn’t did malware execute? It’s something a lot earlier. Wil Santiago: That’s exactly right. When we look at the cyber kill chain, we want to start pushing our adversaries as far left of boom as possible. Right. And so when you hear about this whole right of boom concept, basically, you’ve met your match. And now boom, you’ve now been impacted. Right. And so there’s a lot of indicators of compromise that we can start to hone in on. That will give us an understanding of whether this is legitimate or illegitimate. Right before an adversary even types the command. And again, that’s the context. And the context is what the SOC is really understanding of a customer. Where do they operate? What are their hours of operation? Where are they globally distributed? What’s the infrastructure they use? What are the tools they use? How did they use those tools? Did they deploy tools every Thursday at 2 p.m.? So there’s this constant checklist that they’re doing every single day to understand this. And so when we talk about living off the land, threat actors are trying to execute commands. Right. They’re just trying to sit there. We’re typing on a keyboard command line. Hey, I’m not going to introduce any new factors to my intrusion. I’m just going to live off the land. Ultimately, they want to deploy a payload at the end of all of that. But if they deploy a payload too early in their kill chain, they risk getting caught. Right. And so what they’ll do is they’ll stage everything. They’ll compromise an endpoint. They’ll add a persistent backdoor user. They’ll deploy some small scripts to enumerate the network. Just to get an understanding of what’s happening. But they’ll usually stage those in like a C:UsersMusic folder. And that’s their staging environment. So you can catch them. And we’ve caught at Blackpoint a number of threat actors where their toolkits are still on the machine because we caught them so early left of boom that legitimately all they did was log into a machine, try to mount a share, but it failed. And then that failed share mount is like, wait a second. They have never tried to mount a share on this file server ever. And then you call the MSP and they’re like, yeah, Monday through Friday, our hours are from eight to three and it’s seven p.m. at Thursday. Right. Well, now the context of the intrusion starts to become a little bit more apparent. And so we have to do this very quickly. The reality is for us, behavioral context, it matters more than ever. That is the true bread and butter for stopping threat adversaries is understanding the behaviors in the context of which they employ to compromise the network or compromise an endpoint. And so we focus a lot of our threat intelligence and our adversarial intrusion analysis based off of what hack or tradecraft is. We always say this internally, you cannot protect what you don’t know how to hack. So we spend a lot of our time recreating these attacks, understanding where do we catch them? And one of the things that we found is in those early development cycles of understanding the behaviors of an adversary, we found key indicators of like, wait, that is a very high fidelity indicator that before an adversary even gets on a keyboard, we’ve already caught them. They don’t know that yet. Right. And so that’s a little bit of our secret sauce there. But the reality is that secret sauce was created because we thought like threat actors and we sort of recreated what they did in controlled environments and testing environments to then to make sure the detection and the efficacy of what they’re doing is caught within our product. Robert Dutt: So this is a bit of a sidebar, but it was a new term, at least to me. You flagged Etherhiding in the report, attackers embedding malicious logic and blockchain smart contracts to manage compromised sites. Can you walk me through that real quick? And how real is this in terms of how widely it’s being deployed today? And why does it matter for detection purposes? Wil Santiago: It’s a newer term. You know, I would like to say that we have way too many terms in security and security, you know, sort of like we’re trying to be cool. The reality is this is a technique that leverages transactions on a public blockchain to basically retrieve malicious payloads. Right. And so this is another sort of trend that an adversary is using where they’re just retrieving a payload from something that is trusted. In this case, cryptocurrency. A lot of people trust cryptocurrency. A lot of people trust public blockchains. And so the idea here is that, you know, threat actors are usually going to utilize some type of social engineering and then that social engineering is going to get you to come to like a WordPress site through that WordPress site. They’re going to basically have scripts that you’re going to download and ultimately run. Innocuously. Now, when that happens, you download something that you think is OBS, like the example I gave earlier, it’s actually a JavaScript payload. Well, that JavaScript payload goes and reaches out and it pulls a malicious payload from the ether blockchain. Right. And so that’s that aspect of there’s function calls that we’ve identified within Blackpoint that are related to that remote management of pulling payloads from that blockchain. My personal opinion of this sort of technique is, you know, it gives a lot of advantage to the threat actors in terms of stealth and flexibility. But it is one of those techniques that is complicated for majority of what we see at Blackpoint. Most threat actors are not getting to that complicated level of compromising. They’re just hosting malware on a compromised WordPress site of a legitimate company that they’ve co-opted the passwords for. Right. And again, we see threat actors from different angles. 90 percent of what we see sort of today is cybercrime related. Right. So you have a lot of the fake CAPTCHA, the ClickFix lures, the Etherhiding stuff. The reality is at the end of that payload, we see everything from Etherhiding to Cobalt Strike to ransomware and compromise. The way that they get to that sort of compromise is kind of the same, though. Robert Dutt: Last one for me, if an MSP is listening to this and they’ve just absorbed that, you know, more than half of the attacks they’re going to see start with legitimate credentials, their own tools are showing up in about a third of incidents. MFA isn’t necessarily a guarantee. Where do you start? You know, what’s the one thing they probably aren’t doing today that would meaningfully move the needle for them in terms of making sure things are as locked down, as protected as is possible? Wil Santiago: That’s a great question. I like to say we should probably be spending most of our time right now really focusing on posture and posture management, reducing the attack surface. Right. How do you how do you start? Where do you start reducing the attack surface? This is where frameworks really come into play. And there’s some really great frameworks that are really prescriptive out there. One of them is the Center for Internet Security Controls, CIS version 8.1. It’s very prescriptive and it starts from the very top, right? External facing assets and applications. How do you lock those down? Cloud assets and applications, internal assets, user accounts, passwords, right? And it gives you a prescriptive way to deal with incidents. Beyond that, there’s kind of this like practical implementation groups that they have, right? And so you can start by implementing the CIS Controls with implementing one Implementation Group, right? You don’t have to implement them all. And so I think there’s a subset of Implementation Groups that can be used, but it’s about identifying, you know, what of these sort of subset groups will really resonate with your organization and your maturity level, right? And so I tell most people, look at IG1, start with the essentials. If you’ve already fit the bill on that, then move to IG2, right? But the reality is IG1 is going to give you that foundational security for organizations. And then IG2 and IG3 are going to be a little bit more advanced for more complex things. Most people are probably in that IG1, but they probably could benefit from some of the things in the IG2, the Implementation Groups there. That’s really going to help you really target your defenses against ransomware. That’s going to help you sort of approach a risk-based approach. That’s another thing that, you know, all risk is not the same, right? Risk is treated differently. And it’s important for anyone running a security team to help understand how should I prioritize my risk, right? Where is my risk going to really give me issues if a threat actor gets into it? And therefore, I always say, start there. We all know what keeps us up at night. So that’s the areas that we need to focus on. Robert Dutt: All right. Some sage advice and some sobering numbers as well. I appreciate your taking the time and walking us through some good stuff. Wil Santiago: Thank you, Robert. I really appreciate it. Robert Dutt: There you have it. Wil Santiago from Blackpoint Cyber. I’d like to thank Wil for his time today and for bringing some real energy to what can sometimes be pretty dense subject matter. And of course, I’d like to thank you for listening. The data in this conversation is worth thinking about. More than half of the attacks Blackpoint’s SOC starts with someone simply logging in, using credentials that were stolen sometimes long ago, and that users are still reusing across platforms. A third of triaged incidents involve RMM tools, the same tools your techs are using right now to manage endpoints. And MFA, as much as we’ve come to rely on it, is no longer the finish line it once appeared to be. The antidote Wil describes is behavioral context, understanding what normal looks like in an environment so you can spot when something legitimate is being done illegitimately. Not “Is this malware?” But “Is this person, using this tool at this hour from this location, doing something they’ve never done before?” That’s a fundamentally different way about thinking of detection, and it’s why the human element in the SOC still matters. And I’ll add one thing that Wil mentioned after we wrapped the recording. It’s a dimension of this fight that doesn’t get talked about often enough. Blackpoint’s work doesn’t stop at detection and response. They’re actively working to identify and disrupt adversary infrastructure, notifying law enforcement, including, he noted, Canadian authorities, with the specific goal of making cybercrime economically painful. The logic is straightforward. If your infrastructure gets taken down every time you try to run a campaign, the math of operating a criminal enterprise starts to change. That’s offense, and it sounds like they’re playing it. If you’re finding the show valuable, I’d encourage you to follow or subscribe to the podcast. You can find us on Apple Podcasts, Spotify, YouTube, all the major directories. A rating review always helps. Until next time, I’m Robert Dutt for ChannelBuzz.ca, and I’ll see you in the channel.

Business of Tech
N-able's Security Revenue Faces Decline as License Portability Undercuts MSP Margins

Business of Tech

Play Episode Listen Later Aug 12, 2026 12:21


The episode details a structural shift for MSPs and IT service providers: the separation of security license resale from the value of human-led security services, and the resulting pricing and margin risks. Companies like N-able, SentinelOne, and SonicWall exemplify how technology offerings and delivery mechanisms are forcing providers to re-examine what differentiates their services beyond the products they resell. N-able's financial results illustrate the risk of relying on product-based security revenue. The company reported a drop in annual recurring revenue, driven by lower renewal rates in Unified Endpoint Management and Endpoint Detection and Response lines—both of which relied on reselling portable licenses, notably SentinelOne's product. In contrast, revenue from services tied to human expertise—through the acquired Adlumen's managed detection and response (MDR)—grew, according to both N-able management and analysts. The episode states that when customers can move licenses without losing service continuity, price becomes the only differentiator, undermining provider margins. Related developments reinforce this dynamic. SonicWall launched a combined antivirus and EDR solution available as both a product and a managed service—explicitly marketed for MSP resale—where SonicWall's analysts handle detection and response. Additionally, Proofpoint expanded its managed services platform, providing security, backup, and compliance through an MSP-oriented, multi-tenant console. These offerings blur the line between manufacturer-managed services and traditional MSP-delivered security work, increasing vendor competition at the service layer. For MSPs and IT leaders, these shifts expose the risk in revenue models that bundle security services with third-party product resale, particularly when those products are easily substitutable. The transcript urges providers to re-evaluate their pricing strategies: separating human service from license cost, justifying it independently, and moving away from device- or seat-based billing. The clear risk is that failing to articulate and defend the value of human-led activities will leave providers vulnerable to vendor undercutting and margin erosion, as seen in recent N-able outcomes. 00:00 Recurring Revenue Went Backwards  03:24 They Stopped Saying RMM 06:04 You Already Own It 09:18 Why Do We Care?  Supported by:  Guardz 

SCHWARZ GELB - Der Dynamo-Podcast
#186 Dynamo verpatzt den Saisonstart, DFB-Sperre ausgesetzt & Vorschau auf Darmstadt

SCHWARZ GELB - Der Dynamo-Podcast

Play Episode Listen Later Aug 12, 2026 104:36 Transcription Available


Dynamo verliert das Auftaktspiel der neuen Zweitliga-Saison in Nürnberg mit 0:3, wahrscheinlich die schwächste Zweitligaleistung des gesamten Jahres 2026. Jens Umbreit und Tino Meyer analysieren gemeinsam mit Sportjournalist Patrick Franz (BILD Dresden & MDR), was zum Start fehlte und was Matchwinner Mohamed Zoma für Nürnberg so gefährlich machte. Dazu die Entwicklung um den DFB. Die K-Block-Sperre gegen Dynamo ist für das Heimspiel gegen Darmstadt vorerst ausgesetzt, der Verein zieht vor das DFB-Schiedsgericht. Dazu Stimmen von Torhüter Tim Schreiber, Jonas Sterner, Kapitän Niklas Hauptmann und Trainer Thomas Stamm.

Medizinprodukte – Frei Schnauze
Folge 18: Medizinprodukte Frei Schnauze – viel Neues aus Brüssel

Medizinprodukte – Frei Schnauze

Play Episode Listen Later Aug 12, 2026 42:08


In dieser Folge sprechen wir über aktuelle Veröffentlichungen der Europäischen Kommission und von Team NB sowie über Themen rund um benannte Stellen, den Vorschlag zur Änderung der MDR und IVDR und harmonisierte Normen. Dabei werfen wir insbesondere einen Blick auf das Verfahren und die nächsten Schritte. Gemeinsam mit Frau Flipo und Herrn Trautwein diskutieren wir zudem über die Chancen und Herausforderungen für klinische Studien in der Medizintechnik. Außerdem gehen wir auf die Verpackungsverordnung sowie wichtige Urteile im Medizinproduktebereich ein.

In Focus by The Hindu
MDR charges on UPI transactions: Necessity or revenue grab?

In Focus by The Hindu

Play Episode Listen Later Aug 11, 2026 46:38


Indians make around 24 billion UPI (Unified Payments Interface) transactions a month. The combined value of these payments is nearly Rs30 trillion. UPI is at the heart of India's digital public infrastructure. The best thing about UPI payments: they are free. But now this could change. The government recently passed the Taxation and Other Laws (Amendment) Bill, 2026, in the Lok Sabha. This Bill, among other things, amends the Payment and Settlement Systems Act, 2007, which had ensured that no charge can be levied on UPI transactions. But now, this is no longer the case. The government has claimed that this charge, known as the Merchant Discount Rate (MDR), may only be applied on transactions above a certain threshold, that too only on merchants, and not on consumers. But analysts believe the costs will be passed on to the consumers. Why is MDR needed for UPI payments? Does it have anything to do with US pressure in the context of trade deal negotiations, as alleged by Opposition leaders? Is UPI really ‘free of charge' even as it stands today? Guest: L Srikanth from Cashless Consumer, a consumer collective Host: G Sampath, Social Affairs Editor, The Hindu Producer: Jude Weston Learn more about your ad choices. Visit megaphone.fm/adchoices

ChannelBuzz.ca
Exabeam rebuilds its MSSP commercial model to fix the economics of managed SIEM

ChannelBuzz.ca

Play Episode Listen Later Aug 11, 2026 38:57


Craig Patterson, global channel chief at Exabeam For years, SIEM has been one of those technologies that looked good in theory but was genuinely hard to build a profitable managed service around. Deal-by-deal discount negotiations, licensing structures built for enterprise resale rather than recurring managed services revenue, and no predictable floor on margin. For many MSPs, the math just never worked. Exabeam – the combined company formed from the merger of the original Exabeam and LogRhythm – is making a direct play to change that. Global channel chief Craig Patterson and senior director of service provider alliances Peter Stratis join In The Channel to walk through the new MSSP commercial framework inside the recently launched APEX Partner Program. Two new licensing pathways: a single-pool capacity model for high-volume, multi-tenant environments serving SMB and mid-market clients, and a federated subscription model that isolates customer environments for compliance and data sovereignty requirements. For Canadian MSSPs navigating PIPEDA, OSFI E-21, or Protected B, that second model is the one to pay close attention to. Peter Stratis, senior directof of server provider alliances at Exabeam The conversation also covers Sherpa, Exabeam’s new AI-powered partner enablement platform – a move away from the traditional LMS toward an always-on coaching tool that can join partner sales calls in real time – and Agent Behavior Analytics, Exabeam’s new capability for detecting malfunctioning, misaligned, and subverted AI agents inside customer environments, included at no additional cost. The standout line from Peter Stratis – who called this his first-ever podcast appearance – is the one worth writing down: “We treated our service providers like resellers, unfortunately.” The new framework is a direct acknowledgment of that history, and an attempt to rebuild the commercial relationship from the ground up. Read Full Transcript Robert Dutt: Hello and welcome to In The Channel from ChannelBuzz.ca, bringing news and information to the Canadian IT channel community for the last 16 years. I’m Robert Dutt, editor of ChannelBuzz.ca and your host for the show. If you’ve been in the channel for any length of time, you know that SIEM has always been one of those technologies that seems great in theory but has been genuinely hard to build a profitable managed service around. Licensing models that weren’t built for multi-tenancy, unpredictable costs, discount structures that made margin planning more of a guessing game than a business model. A lot of MSPs have looked at the security operations space and quietly backed away for exactly those reasons. Exabeam, the combined company that emerged out of the merger of Exabeam and LogRhythm, is making a direct play to change that. They have overhauled their channel program into what they’re calling the APEX Partner Program and at the centre of it is a new commercial framework built specifically for managed security service providers. Two distinct pathways: one for high-volume multi-tenant environments and one built with compliance and data sovereignty in mind. For Canadian MSPs navigating PIPEDA, OSFI E-21 and Protected B requirements, that second lane is worth paying close attention to. I’ve got two Exabeam executives here to walk us through it. Craig Patterson is Exabeam’s global channel chief and Peter Stratis is the senior director of service provider alliances, the person who’s been working directly with MSSPs to build this out from the ground up. Let’s get right into it. My chat with Craig Patterson and Peter Stratis. Gentlemen, thank you for taking the time. Craig Patterson: Thank you, Robert. Super excited to be on here with you today, my friend. Peter Stratis: Thank you. Robert Dutt: Craig, can you just kick us off with a quick version of where Exabeam sits right now? You know, you guys went through a significant merger with LogRhythm not that long ago. Now you’re pushing an updated partner program. For solution providers who maybe haven’t been following closely, what does the combined company look like from a channel perspective? Craig Patterson: The short answer, my friend, is that we’re sitting in an amazing place. We’re absolutely in a good place positioning to really drive value to our partner community. And so to give you a little more context around that, like you asked, we’ve spent the last 12 months really kind of rethinking, reimagining the whole partner ecosystem in a way to create value for all of our partners globally. And so there was a number of things we went through over the last 12 months. We spent a lot of time really going to this assessment loop, understanding everybody’s perspective. So we did that by having very strategic conversations with our top-tier partners. We did some survey work. We looked at the broad landscape in terms of the trends that the partners are really looking for in these modern channel programs. So all of that really became this assessment loop. The output of that is that really became the foundation for what we built here with APEX. And so with APEX, the Exabeam APEX Partner Program, what you have here is you have a program that’s really centered on value that’s really focused on solving a problem that exists in our market today around enablement. And so when you think about enablement today, I’ve written a lot of articles on this. Most enablement programs really don’t drive to the level of outcome that companies are looking to have. Outcomes like conversion rates, outcomes like time to first deal, outcome rates like retention rates, all these things. And so what we’ve done is we’ve really focused on enablement as the key catalyst to really drive value to our partners. And so with that, we’ve launched new enablement programs really with a focus on increasing their competency level so we can align to those outcomes we’re looking to have with our company’s operating plan. And so there’s a lot of thought that’s got into this. The short answer is we have a program that’s built on value. It aligns to where the market is going and what partners are really asking for. Robert Dutt: Peter, your title as senior director of service provider alliances is a pretty specific role. Can you tell us a little bit about what that looks like sort of on a day-to-day basis and the big problems that you’re focused on? Peter Stratis: Sure thing. Thanks, Robert. Well, I’ve been with Exabeam for about eight years now and service providers have always been a key component of not only our channel strategy, but our go-to-market and just from our net new revenue perspective. After our merger with LogRhythm, that actually continues and if anything, it’s only been more emphasized because both from an on-prem and from a cloud perspective, we see the MSSPs being a strong driver of that strategy of our go-to-market. So over the last eight years, we’ve seen that trend of not only on net new revenue, net new logos being a major part of our business, but then how do, to Craig’s point, how do we support them? To be quite honest, in the past, it was quite difficult. We really didn’t have any kind of structured pricing for these partners. It was, to say the least, it was more of a resale program that had some discounts tied to it. So through Craig’s efforts, through our whole surveys and our intent to really go after this market and treat them the way they should be treated, he mentioned that we did these surveys. We asked internally, what do you look for in a service provider partner? We asked externally what these partners were looking for from us. And that’s when in building the APEX Partner Program here at Exabeam, we also took into account what service providers would look for in a new partner program. So that’s everything from pricing to support. Craig mentioned enablement. Enablement is a huge part of that, where they felt in the past they were just lumped up as just a regular partner. Now we have supported APIs, documented APIs that most, if not all, of our partners are using as part of their foundation for their services. So we’ve really come a long way and continue actually to build upon that, as you’ll see throughout 2026 and beyond. Robert Dutt: Okay, let’s get into the framework itself. You guys positioned it at launch as solving commercial and operational friction for MSSPs. Curious, what did you hear that friction looked like in practice? What were MSSPs telling you was broken or was a big challenge? Craig Patterson: Yeah, so I’ll take a stab at this and I’ll let Peter give more context. So a lot of this came out during that assessment phase. Robert, we’re talking to the MSSPs globally. I’m like, what’s working? What’s not working? What would they like to see incorporated into the MSSP program 2.0? So a lot of the feedback we heard was really around the flexibility. Being able to have a license that is catering to all the customer demand they have beneath. So it’s really giving them the flexibility to buy that one license and carve it up as they see fit. And giving them more flexibility on the commercial terms. That was a lot of the commentary we heard. The other thing we heard was really they wanted more value as it leads to the enablement side. So obviously getting them enabled on the pre-sales side, but more importantly on the post-sales side. So they could actually drive those implementations, drive the management and really help those customers create a lot of value. And so I think those were kind of the big levers that I heard from those assessments. And then in practice, Peter can give you some more context in terms of how we’re putting all this together. Peter Stratis: Yeah, thanks Craig. A lot of what we heard from the service provider community in the past was friction. So when they’re trying to price out their services and our product and etc., they were seeing friction at onboarding. They were seeing friction in trying to predict their margin on deals. As mentioned, not airing any dirty laundry here. It was more like a resale program. So we gave discounts and there were very opportunistic discounts on a deal-by-deal basis. So they didn’t build predictable service models around it in the past. And then you always hear the buzzword, multi-tenancy. We kept on getting asked about our multi-tenant roadmaps, etc. We’re looking at this framework as a way of solving for that. We continue to make feature enhancements into the platform that will strive for that multi-tenancy. But the way we’re solving for it is by these two pathways. One is that single license, pooled capacity, data segregation model. And the other is that federated workflow that we announced where it’s more for, whether you’re within data sovereignty, if in different regions or just different use cases from a compliance perspective, whether it’s healthcare or finance, and you have to keep these environments isolated. We have a plan and we worked with our MSSPs specifically to have these kind of pathways. So we heard from our MSSPs and we actually developed these two pathways with them in mind. So they were in the design phase and in the rollout phase for both federated and the single pool capacity. Robert Dutt: The federated model is such an interesting one, I think, for the Canadian market, specifically data sovereignty, huge topic. And there are specific compliance requirements, PIPEDA, OSFI E-21, Protected B status. It means that a lot of Canadian MSSPs can’t just kind of throw everything into one pool. Was that the sort of thing that was explicitly on the radar when you built this out or a happy coincidence of the architecture and the feedback that you heard along the way? Peter Stratis: It’s actually a little of both, right? So it just so happened to be the maturity of our platform. Even from our Exabeam New Scale platform, we went from an on-prem hardware appliance way back in 2012, to our version 1.0 was a SaaS product, to our native cloud. It was always a single-tenant solution. So it worked well for certain service providers that had the capacity. They had their APIs and their own platforms that could manage this solution. As you heard more and more about multi-tenancy and the need for data sovereignty and all that, we still had a big part of our MSSPs were asking for this single license pooled capacity. So we structured it in a way where for midsize organizations or even some small, medium business, you still have that single pool capacity using data segregation. You lose some of the customization, but you could actually solve for a lot of those customers in that model. And then you have another plan with the federated. So the more mature MSSPs are running both models in some capacity. They could still run that single license for their SMB play. And then for either large enterprise or very compliance-driven customers that want those isolated environments, they have that flexibility. And that’s what we built a framework around. Obviously, that’s one point of feedback that sort of directly informed the framework. Robert Dutt: You guys have said that this whole thing was built, as you said, with direct collaboration with your MSSP partners rather than kind of coming down on high. I’m curious along with what you’ve touched on already, what actually changed as a result of going through that process? What did you go in thinking you’d build and how did it come out differently because of what partners told you along the way to building it? Craig Patterson: Yeah. So I think there’s a lot of things that have been addressed. Obviously, the packaging and the commercial aspects as Peter was describing, but think about some of the fundamental problems in terms of partners want this path to profitability, right? Really understanding how they can create margin. That was one thing. Another path is like, how do I become enabled with Exabeam? And how do I stay informed in terms of where you’re going? Another problem we wanted to solve. So I think it’s a lot around the financial aspects of doing business with us. A lot of it’s around becoming enabled, becoming more knowledgeable on all the new features and releases that we’re dropping. And so those were some of the big fundamentals that we wanted to solve in the APEX framework. And then beneath that, obviously, is the whole MSSP play. And that’s what Peter’s been talking about. So you can probably give a little more context on that. Peter Stratis: Yeah. As mentioned, there is no one-size-fits-all. So the feedback we were getting was obviously their security platform was important to them. Some of them had an in-house platform they built on their own. And there’s ways of differentiating. So basic SIEMs are just going after alert monitoring. So how can I differentiate my service if I’m a service provider? Well, there’s ways of going to market, but also there were things we needed to do in the back office from a platform perspective to make those possible. So making our behavioral analytics available in these models so they can actually differentiate their services. As I said, we have a history of actually adding features quarter-over-quarter, month-over-month. So that’s not stopping. We didn’t announce necessarily multi-tenancy to the world. We announced a commercial framework for that. So you’ll continue to see on a month-to-month, quarter-over-quarter basis, features added to support not only the commercial framework, but the underlying platform to make it easier for service providers to add that operational efficiency, to add those differentiators from a product portfolio as well. Robert Dutt: Let’s talk about the economics underneath there. You use the term predictable margins as a phrase that shows up in the messaging. SIEM has historically been a tough service to make money on. Licensing models that didn’t fit the managed services motion, unpredictable costs on data ingestion, those sorts of things. What specifically changes for an MSSP’s P&L under the framework? Craig Patterson: Yeah. So I think there’s really two components here. The first is the whole financial package associated to the MSSP partners. And the second is the discounting framework. And so let’s maybe start with the discounting framework. One of the observations that we made during this whole assessment phase was the vast majority, Robert, of all of our deals were flowing through this non-standard process, which means the discounts that were aligned to the traditional framework were not putting the MSSP partners in a position to actually transact. And so what we did is we went through and we re-looked at the discounting framework and sort of realigned it based upon our actual data points. We looked at the last 12, 24 months, the discounts that were being derived to actually transact. And we sort of rebuilt the entire discounting framework for our company in a way that really empowers the MSSP partners now to have enough discount to actually transact without going to this non-standard queue. So what does it mean? Well, we really kind of flipped the script. Instead of 80% being non-standard, we believe 80% will flow through the standard process now because we’ve built the discounts in a way to align with what the market is looking for. That’s kind of the key component number one. And then as it relates to the discounting side, we reimagined how those discounts are calculated. And so now you kind of have your standard program discount. So that’s based upon your tier. So top-tier MSSP partners get the highest level discount. The second is deal registration. Obviously, they put the deal reg in that ties to a discount. Those are both standard common things. But what’s new, which is what you care about. What is new? Well, we’ve aligned the third discount based to their competency level. And so we measure that based upon certifications. And so if you think back to those choose-your-own-adventure books as a kid, we’re really giving the partners their own choose-your-own-adventure. And if they want to drive to the highest level discount, well, simply, MSSP partners got to go take all of our certifications, pre-sales and post-sales, so they have the highest level of competency to drive our services in the market. And our thesis around that is partners that have higher certifications, they’re going to be more active, they’re going to be more interested, they’re going to drive more pipeline. And if we do this the right way, Robert, they’re actually going to convert at a higher percentage, we’re going to see shortened sales cycles, all of which align to the operating plan of our company. So it’s kind of those two fundamental things that were addressed through that process. And then I’m sure Peter can fill in the detail for you. Peter Stratis: Yeah, if I can actually elaborate on that. Thanks for that, Craig. And just some historical context, Robert, as mentioned in the past, we treated our service providers like resellers, unfortunately, so it was very deal-specific in terms of what they were getting on a deal-by-deal basis from a discount. So the economics of it was they really couldn’t rationalize their margin predictability on an overall services basis. And you know, different regions go to market different ways. In Europe, Asia, Latin America, predominantly, it’s all SIEM as a service and MSSP owns the license. In the Americas, both US and Canada, we saw a lot of proliferation in the past of customer-owned licenses. So the MSSP would resell the license, and consequently, just provide managed services wrap on top of that. Not only do we see more of that MSSP-owned model now where it’s SIEM as a service in the US and Canada. So it’s proliferated itself throughout all the regions. Now with these frameworks, we actually are able to build these economics, the margin predictability, as Craig mentioned, because now they know as a standard, what they’re going to be selling for. So especially as we do this federated model, and even the single license, you know what your price is across the board, you know what license you’re buying, you know what price you’re buying it for, you know, the more customers you add to these models, the more your profitability will increase as well. So it continues to grow from a pure profit play. Partners want to know what their margin would be as their customer licenses grow. And this is exactly what the framework did. Robert Dutt: This is sort of a broader question around MSP/MSSP distinctions as opposed to directly about the framework. But there’s a distinction worth drawing between an MSP trying to bolt a security practice onto the existing managed services business and the established MSSP who’s been at this for a year or who has built it up. Are those two different conversations for you? And if so, what are the different entry points and care-abouts? Peter Stratis: So it’s interesting, not only because of this announcement, even prior to it, the announcement of the APEX Partner Program here at Exabeam caused a lot of interest from partners and different kinds of partners. The traditional MSP, when inquiring, it was kind of hard when we were vetting them that they had no security practice of their own. So oftentimes they would actually outsource that security to an MSSP, to a classic MSSP, or maybe just resell services from those other organizations. We see that, we see a lot of interest from MSPs with that. And we see VARs or resellers come to us that want to build managed service practices as well. So we look at both of these in two different ways. One, how can we take care of these partner inquiries now, and then how can we grow with these organizations? So both MSPs and resellers that are interested in managed services now, our first inkling is to try to introduce them to our current managed service base. These people have the experience, they have the certifications, they have the technical knowledge. We’ve seen that move from a lot of MSP partners actually having channels of their own. So they actually sell their MDR or MSSP services through a channel of resellers or MSPs. But then if that’s our first step with these type of partnerships, then it’s like, how can we grow within your organization? How can we help you get the technical skills required? Because for a true MSP to have success, not only in SIEM, but just security as a service, you can’t just train one or two people, you need the 24-by-7 support, you need the tier one and tier two level of support services as well. So you have to grow your organization or outsource it to people that are already prepared to handle that. So that MSP play, we actually see it more and more going towards our current managed security service providers and getting that as a resource. Craig Patterson: Just to add a little more context to that too. So this actually becomes a very interesting point for the distributors worldwide as well. Because a lot of what they provide in terms of value is helping those MSPs in terms of deployment and management of the services. And so we’ve gone through the vetting process globally, looking at all of our distributors and we’ve handpicked our strategic distributors around the world. So if we have MSPs that want to come into the program, but they’re not ready on that post-sale side, well, guess what? That can become the role of the distributor. And secondarily, this is where the enablement really comes into play as well. And so that’s why we’ve built very specific paths on enablement, pre-sales and post-sales, where partners can choose their own adventure. “Hey, if I want to get going on the pre-sale side, well, guess what? I can simply resell.” Or, “Hey, I want to really start focusing on the post-sales services implementation.” I can start to take the enablement around those courses to become more of an expert to really give me those new capabilities. And so there’s a whole conversation around what we’re doing on enablement with our brand new Sherpa that’s really given a lot of these partners those capabilities. Robert Dutt: On the note of Sherpa, an AI-powered tool for partners, it’s essentially a virtual channel account manager in terms of enablement, onboarding, that sort of thing, especially for an MSSP who’s new to SIEM. How does it change the friction of getting started with Exabeam as their platform? Craig Patterson: You’re going to love this. You’re going to love this. So we’ve sort of reimagined all of the enablement. Again, when you look at traditional enablement, it’s like most enablement is built in these LMS platforms. Like, “Hey, partner, go log on to this LMS platform, get your certification, and then we expect you to actually know what the hell you’re doing.” Reality is that’s not what happens. They log on to the LMS platforms. They fast-forward as quickly as they can to the end. They turn the volume down. And then when the quiz comes, they use AI to answer the questions. And so they just find a way to get the certification. The reality is none of that helps them be better in life or actually raise their competency. And so that’s a problem we took on head-on with Sherpa. And so Sherpa was built in a way to really change the way partners learn with the whole goal of raising their competency level so they can be better on the market. And there was really like three use cases we were trying to solve with the emergence of Sherpa. The first is like you think about this global ecosystem that Peter and I have. We have 3000 partners. The partner ecosystem looks different. We have VARs. We have MSPs. We have MSSPs. We have distributors. We have the trusted advisor market as well. All of them have different needs in terms of where they are from a learning perspective. And so the first use case, Robert, is simply like a tool to be able to ask questions. What are the use cases? How do I position this? Why is SIEM or UEBA better than the competition? Just an always-on tool for partners to ask questions. And so that was kind of use case one. And then the cool thing around that is you think about the ecosystem being very global in nature. The other problem with LMS platforms is I’ve got partners in Japan. Well, that means the LMS platform they log on to needs to be able to talk to them in Japanese. And so the beauty with Sherpa, it does all the translation for us. And we’ve got 15 plus languages that are now live in Sherpa. Partners in Japan are talking to it. We got partners in India and all over the world really asking questions in terms of how we position our services. And that integration can be done by just logging on to our portal. You’ll see a bot pop up. They can just simply ask a question. It integrates in Teams, integrates in Slack. So that was use case number one. Use case number two was we reimagined the whole enablement certification platform. And so it’s a very dynamic learning experience. And so the way it happens is you log on, there’s a topic that you like, you click on that, you start learning, it asks you questions, it asks you to position services, and then you record your answer to how you’re actually positioning those services or the features. And it gives you feedback like, “Robert, you did really good on this aspect, but next time you should use this and this.” Or, “Robert, if you’re talking to a customer that’s in this vertical, you should talk about this use case because that’ll help resonate.” And so the whole certification process has been rebuilt and that’s the second use case. The third use case, this is a game changer. And this really goes to your question. And it’s an always-on coach. And so partners are now able to invite Sherpa to calls. And so as they’re having those conversations with customers, and the customer may say something or give them an objection, well, in the background, Sherpa will give them the answer to that objection and say, “Customer said this, talk to them about this.” Or, “Have you shared this new feature that was just released in the quarterly launch?” So it’s like this always-on coach, always-on assistant to really give them what they need. And then we’re putting it on this innovation roadmap. And so every single quarter, we’re launching new innovation in Sherpa. As an example, we’re now launching our LinkedIn integration. So if you’re an MSSP partner, you log on to Sherpa, you’re connected to LinkedIn, it’s going to ask you, if Sherpa can look through your network to find customers that may be a good fit for our services. And then it’ll say, “Okay, great. We found these contacts. Should we go ahead and write the campaign? Should we write a campaign that you can use to send to those customers in your ecosystem on LinkedIn?” And so quite honestly, I think we’re bleeding edge in terms of really being able to use AI and adopt AI in a way to drive good outcomes, well beyond where most companies are with their simple ChatGPT things like that. We’re actually driving outcomes. Robert Dutt: The rise of AI baked into the partner program and partner tools is a fascinating space for me to watch. And that certainly, you make a compelling case for the role of Sherpa there. That sounds really interesting. A quick one on the product side, not directly related here, but just out of curiosity, Exabeam just dropped Agent Behavior Analytics in your April release, sort of extending behavioral detection to AI agents, ChatGPT usage, Copilot activity, those kinds of things. For an MSSP looking to take this to market as a service, is it a new revenue line? Is it an upsell? Or is this sort of becoming table stakes that clients expect to see bundled into what you’re doing for them? Craig Patterson: I’m glad you asked. It was just recently at RSA, the conference, obviously AI is the buzzword, but what do you do with that? When we presented the agentic behavior analytics to a lot of our partners or potential new customers, the question that was often asked was, “Well, how much is this extra?” And that’s not how we license our product. So the behavior analytics has been part of our solution since our inception from our analytics model. So specific to AI, this is going to be, you could differentiate your service from other service providers by using this behavior analytics, but by no means is it an extra cost on the MSSP’s behalf. So they’re going into an organization that has a thousand users, human entities, and overnight they now have 10,000 non-human entities. We look at and model all of them using our analytics. So now you actually have at least a basis of what’s normal from a behavior standpoint for both non-human and human entities. So we really change the game, but haven’t changed the pricing along with it. So it comes naturally within our platform. So no change for me as a partner, but if I can find a way to upsell based on it, all the better. If not, I add additional features. Hopefully my customer is more happy. Peter Stratis: I was just going to say, if you look at the macro trends we’re seeing, this is the number one conversation that’s being had right now, especially like you look at the financial sector. Every single company is facing this problem. And so this really, not only does it give them a new use case to go after, I think it just makes the overall security services of Exabeam more relevant based upon what’s happening in the overall market, which all that makes the revenue stickier, makes those conversations more impactful that those MSSP partners are having. Craig Patterson: Yeah. Well, what I’m going to mention is operational efficiency and service differentiation is what’s key to our MSSPs and their success. So the license is foundational. And now that we’ve actually solved for being predictable from a margin perspective, how can they differentiate themselves, making them operationally efficient using automation, using our threat detection, and then also the service differentiation. And the other thing too, just thinking through this a little bit, I mean, there’s different AI agents that exist out there that are doing different things. You think about the malfunctioning agent, the one that’s just off base and it’s doing things that are just incorrect based upon the fundamentals or foundation of the AI agent. That’s one thing that gets addressed by looking at the abnormal behavior. The second is the misaligned agent, the ones that are pursuing goals in a way that could negatively impact the company. And that gets a little bit more scary. But really what gets scary is those subverted agents, the ones that have been hijacked that are actually causing harm. And so you think about all those different use cases that are happening, and that’s the beauty of what we just released is our new ABA, sort of creating this new category in the market. That’s really what our ABA is looking for, is all those different things that are happening, whether it’s misused, misaligned, or subverted. All that can be detected through this new agent behavior. Robert Dutt: Okay, last question for me. If I’m an MSP who’s been sitting on the sidelines, I’ve been thinking about them or are upgrading my security operations practice. What’s one thing that you wish I understood about the opportunity and the economics, but I probably don’t at this point? Peter Stratis: It’s all about how they actually start off. They’re interested in selling managed security, but they don’t know that they have to standardize their delivery model. They can’t make it where every customer is custom, because that’s when that price predictability goes away. So everything from onboarding to customizing your offering has to go away. You might be able to do it for a certain amount of customers, but you have to build a model that’s repeatable. Automation is going to be very important to that. And then finally, you could add optional add-ons, but you have to resist the temptation to over-customize everything. The great thing about what Craig has done with the APEX Partner Program and the way we built it out here at Exabeam is it supports all of this through all the enablement efforts. So Craig mentioned all the enablement built into the program, but then we have certification tracks. So we’ll help you along in that process. And we have everything from APIs and the use case and the scripts to help you automate that track for you to make it easier, but just don’t jump in and try to do a custom solution for each customer. Robert Dutt: Gentlemen, I thank you very much for your time. Once again, I appreciate your walking us through the commercial framework. Craig Patterson: Thank you, Robert. Appreciate it. Peter Stratis: Thank you, Robert. Robert Dutt: There you have it. Craig Patterson and Peter Stratis from Exabeam. I’d like to thank Craig and Peter for their time today. And a special note, this was Peter’s first podcast appearance. You never would have known it. A few things I’ll leave you with. First, if Peter’s candid admission landed for you — that Exabeam used to treat service providers like resellers with opportunistic deal-by-deal discounts that made it impossible to build a predictable margin — sit with that for a moment. Not unique to Exabeam. That was the industry. And it goes a long way to explaining why so many MSPs have struggled to make managed SIEM work as a business. The new framework is a direct attempt to fix that math. Two pathways: a single-pool capacity model that works well for SMB and mid-market clients, and a federated model that isolates environments for compliance-heavy customers. The discounting structure has been rebuilt from the data up with the goal of moving 80% of deals through a standard process. Up from what Craig described as the opposite of that. The Sherpa AI tool is worth watching closely, not just as a training platform replacement, but as an always-on coach that can actually sit in on partner sales calls and surface real-time objection handling. The LinkedIn integration is coming next, and it starts looking less like an LMS and more like a business development tool. And the closing advice I’ll leave you with is Peter’s. If you’re an MSP thinking about entering the security space, standardize your delivery model before you take on your first customer. Resist the urge to customize every environment. That’s exactly where price predictability and profitability goes away. Thanks as always for listening. In The Channel is available on Apple Podcasts, Spotify, YouTube, and all the major podcast directories. If you’re finding value in the show, leave a rating or review. It goes a long way to helping other folks in the channel find us. Until next time, I’m Robert Dutt for ChannelBuzz.ca, and I’ll see you in the channel.

NDR Info - Echo des Tages
Drohnenvorfall in Leipzig: Wie können wir uns besser schützen?

NDR Info - Echo des Tages

Play Episode Listen Later Aug 6, 2026 24:41


Die Bundesanwaltschaft hat die Ermittlungen zum mutmaßlichen Anschlagsversuch mit einer Sprengstoff-Drohne am Flughafen Leipzig/Halle übernommen. Grund sei die besondere Bedeutung des Falles, teilte die Behörde in Karlsruhe mit. Es bestehe der Verdacht des versuchten Herbeiführens einer Sprengstoffexplosion sowie des gefährlichen Eingriffs in den Luftverkehr. Sachsens Innenminister Schuster hat inzwischen Darstellungen widersprochen, die ukrainischen Flugzeuge seien mit Munition beladen gewesen. Beide Maschinen waren leer, sagte Schuster dem MDR. In der Nähe des Flugzeugs war in der Nacht zum Mittwoch eine Drohne entdeckt worden, die mit Sprengstoff bestückt war. Woher die Drohne stammte, ist noch nicht bekannt.

The IT Pro Podcast
SPECIAL EDITION: Shifting from traditional MDR to an AI-powered agentic SOC

The IT Pro Podcast

Play Episode Listen Later Aug 5, 2026 39:40


In this episode, brought to you in association with Arctic Wolf, Jane speaks with Nick Dyer and Carl Adasa about moving from traditional MDR to an agentic SOC.

BusinessLine Podcasts
Top Business & Market Headlines Today — BL Morning Report, August 5, 2026

BusinessLine Podcasts

Play Episode Listen Later Aug 5, 2026 3:16


Markets adjust to new closing auction mechanism Markets witnessed a volatile trading session as investors adjusted to the new closing auction mechanism introduced for stocks with futures and options contracts. Snapping a four-day winning streak, the BSE Sensex fell 210 points to close at 78,428, while the NSE Nifty declined 159 points to settle at 24,615. Despite sharp intraday swings, trading remained orderly, suggesting that market participants are gradually adapting to the new framework. Turnover in the closing auction session also remained healthy. The NSE recorded more than ₹1,540 crore in turnover on the second day of the mechanism, up from ₹1,276 crore on Monday, while the BSE saw turnover of ₹9.35 crore. Dabur defends product purity amid FSSAI action While financial markets were adjusting to a new trading regime, the consumer goods sector was grappling with regulatory scrutiny. Dabur India has defended the quality and purity of its products after the Food Safety and Standards Authority of India (FSSAI) prohibited the sale of certain food products over the use of “100 per cent” claims. The FMCG major said it has never made misleading claims and has already begun updating product labels, advertisements and website content to remove the “100 per cent” wording. According to the company, most affected products have either completed the transition or are in the process of doing so. Dabur also said it is engaging with the regulator and seeking legal advice on the way forward. India's app economy hits record high From product labels to digital subscriptions, changing consumer behaviour is becoming increasingly visible across sectors. India's mobile app economy posted its strongest quarter yet, with revenue reaching a record $345 million during the April-June quarter of 2026, according to data from Sensor Tower. The figure marks a 35 per cent year-on-year increase, driven largely by spending on AI applications, video streaming platforms and other digital services. Non-gaming apps alone generated nearly $240 million in revenue, growing more than 50 per cent from a year earlier. The latest numbers suggest India is steadily evolving from being the world's largest app-download market into one where consumers are increasingly willing to pay for digital services. Centre moves to reintroduce MDR on UPI for large merchants As digital adoption accelerates, attention is also turning to the payment infrastructure that powers this growth. The Centre has initiated amendments that could reintroduce Merchant Discount Rate (MDR) on UPI payments made by large merchants. The proposal is part of the Taxation and Other Laws (Amendment) Bill expected to be tabled in Parliament. Alongside this, the government has proposed extending tax benefits for foreign companies supplying machinery to contract manufacturers until 2041, a move aimed at boosting domestic electronics manufacturing and supporting investments from global technology players. The proposed measures are expected to strengthen India's manufacturing ecosystem while also reshaping the economics of the country's rapidly expanding digital payments network. (Research and VO: Siddharth Mathew Cherian)

Ich glaube, es hackt!
50 Milliarden Dollar? Ich frag mal meine Bank…

Ich glaube, es hackt!

Play Episode Listen Later Aug 4, 2026 63:38 Transcription Available


KI-Labels, Musikklau und Milliarden für Rechenzentren – was passiert gerade? In dieser Folge von „Ich glaube, es hackt!“ geht es einmal quer durch die spannendsten Entwicklungen der KI-Welt. Los geht es mit einem Nachtrag zur Diskussion um Open-Weights-Modelle und der Frage, warum ausgerechnet ein chinesisches KI-Modell bei der Abwehr eines Cyberangriffs erfolgreicher war als amerikanische Modelle mit strengen Guardrails. Anschließend werfen wir einen Blick auf die neuen EU-Regeln zur Kennzeichnung KI-generierter Inhalte. Was bedeuten die neuen AI-Labels? Wann muss ein Bild oder Video gekennzeichnet werden? Und wo liegen die Grauzonen zwischen Bildbearbeitung und echter KI-Manipulation? Danach wird es juristisch: Die GEMA hat gegen den Musikgenerator Suno einen wichtigen Erfolg erzielt. Wir diskutieren, warum das Urteil für die gesamte KI-Branche weitreichende Folgen haben könnte und weshalb die Berechnung eines möglichen Schadensersatzes alles andere als einfach werden dürfte. Außerdem sprechen wir über die gigantischen Investitionen in KI-Infrastruktur. OpenAI sucht Finanzierungen in Milliardenhöhe für neue Rechenzentren – und ausgerechnet Nvidia hilft dabei mit. Entsteht hier die nächste große Technologieblase oder erleben wir lediglich den nächsten Schritt der Digitalisierung? Zum Abschluss gibt es wie gewohnt jede Menge Technik-Kuriositäten: Warum manche Mobilfunknetze Telefongespräche nach zwei Stunden automatisch beenden, wie sich Dateien per QR-Code übertragen lassen, warum München endlich die Papierunterschrift abschafft und welche kleinen Tools den Alltag auf dem Mac deutlich angenehmer machen. Themen dieser Episode Open-Weights vs. Closed-Source-KI KI bei der Cyberabwehr Neue EU-Kennzeichnungspflicht für KI-Inhalte Deepfakes und AI-Labels GEMA gegen Suno AI Urheberrecht und KI-Training OpenAI sucht Milliarden für Rechenzentren Nvidia finanziert KI-Infrastruktur Smartphone-Telefonate mit Zeitlimit Datenübertragung per QR-Code Digitalisierung der Verwaltung Praktische Mac-Tipps -- Links zur Folge immer auf https://podcast.ichglaubeeshackt.de/ Wenn Euch unser Podcast gefallen hat, freuen wir uns über eine Bewertung! Feedback wie z.B. Themenwünsche könnt Ihr uns über sämtliche Kanäle zukommen lassen: Email: podcast@ichglaubeeshackt.de Web: podcast.ichglaubeeshackt.de Instagram: http://instagram.com/igehpodcast

Techzine Talks
Hoe hou je AI onder controle, zowel binnen als buiten het SOC?

Techzine Talks

Play Episode Listen Later Aug 3, 2026 48:18


In deze aflevering van Techzine Talks gaan we met gasten Erik de Jong (Chief Research Officer, Tesorion) en Eric van Gent (CEO, Tesorion) diep in op waar AI en cybersecurity elkaar raken. Aanleiding zijn onder andere de recente incidenten waarbij OpenAI-agents op eigen houtje de sandbox verlieten en naar Hugging Face gingen, en waarbij Claude-agents van Anthropic doelbewust een echt bedrijf benaderden terwijl ze wisten dat het geen fictief testbedrijf was. Wat zeggen die incidenten over de volwassenheid van AI-beveiliging bij de grootste spelers?De twee gasten geven niet alleen hun mening over wat er allemaal gebeurt op het gebied van AI en cybersecurity. Ze vertellen ook hoe Tesorion AI inzet in het eigen Security Operations Center (SOC). Denk aan de inzet van een eigen getraind model in een eigen tenant, waarbij de analist altijd eerst zelf een analyse doet en die vervolgens verifieert met de LLM-output.De discussie gaat ook over Shadow AI, prompt security, de keuze tussen gesloten en open-weight modellen, soevereine modellen in Europa, en de gevaren van 'platformization' waarbij niet-securitybedrijven ineens managed detection & response gaan aanbieden op basis van AI-tools waar ze geen controle over hebben. Tot slot bespreken we met onze gasten hoe het zit met de financiële kant van AI.Een eerlijk, technisch en praktisch gesprek over wat AI nu al kan in security, wat gevaarlijk is, en hoe je als organisatie controle behoudt.• OpenAI-agents ontsnappen uit sandbox via een zero-day in een proxy• Claude-agents benaderen een echt bedrijf terwijl ze wisten dat het geen testomgeving was• Shadow AI blokkeren werkt niet: 20% vindt altijd een omweg, faciliteer het gecontroleerd• Prompt security als oplossing om inzicht te krijgen in wat medewerkers in AI-tools stoppen• Hoe gaat Tesorion zelf om met AI in het SOC?• Automatisch ingrijpen als tegenwicht tegen de dalende time-to-exploit• Soevereine, in Europa gehoste modellen worden steeds relevanter voor autonomie• Tokenomics en inferencing-kosten kunnen dienstverlening onverwacht duur maken• Niet-securitybedrijven die AI-gebaseerde MDR aanbieden zijn een zorgelijke ontwikkeling• Kwaliteitsbewaking van AI-output in het SOC blijft de grootste uitdaging0:07 Introductie: AI en security1:07 OpenAI-agents ontsnappen uit de sandbox3:56 Claude-agents en het gevaar van rogue AI9:49 Shadow AI: controleren in plaats van blokkeren13:24 Gesloten vs. open modellen en soevereiniteit20:55 AI in het SOC: use cases en kwaliteitsbewaking25:52 Automatisch ingrijpen en zero trust40:00 Kosten van AI en tokenomics

FIGARINO Geschichten
Gefangen im Maislabyrinth

FIGARINO Geschichten

Play Episode Listen Later Jul 29, 2026 28:03


Na, wo geht es lang? Figarino und Long John wissen, dass jeder Schritt in die Verirrung führen könnte. Dabei wollten sie doch nur mal ausprobieren, wie es sich so anfühlt, umgeben zu sein, von unzähligen Maiskolben und Irrwegen. Ob sie aus dem Feld wieder herausfinden? Vielleicht kann jemand oder etwas ihnen dabei helfen? Ganz gut ist es auf jeden Fall, dass Figarino kratzige Wollsocken dabeihat! Während der Fahrradschrauber und Long John einen Ausweg suchen, begibt sich Reporter Ben am Petersberg im Saalekreis direkt hinein ins Abenteuer auf der grünen Erlebnismeile. Er will das Zentrum des Labyrinths erobern und dabei möglichst alle Stations-Stempel einsammeln. Autorin: Franziska Anna Opitz KarkTon und technische Realisierung: Holger KliemchenReporter: Ben Garit HernandezVerantwortliche Redakteurin: Sandra M. Hänel In den Rollen:Raschid Daniel Sidgi als Figarino und sein Piratenkater Kater Long John Silver Geeignet für Kinder ab 8 Jahre

Das Interview von MDR AKTUELL
Wie der MDR über den Wahlkampf in Sachsen-Anhalt berichtet

Das Interview von MDR AKTUELL

Play Episode Listen Later Jul 24, 2026 3:34


Der Wahlkampf in Sachsen-Anhalt nimmt Fahrt auf. Die Parteien buhlen um Wähler und Aufmerksamkeit. Für eine ausgewogene Berichterstattung folgt der MDR klaren Regeln. Ein Gespräch über das Wahlkonzept mit Jens Hänisch.

MDR KULTUR Unter Büchern mit Katrin Schumacher
Neue Romane von Heinz Strunk, Comic aus den Knast und Graphic Novel aus Leipzig

MDR KULTUR Unter Büchern mit Katrin Schumacher

Play Episode Listen Later Jul 21, 2026 56:23


Heinz Strunk: "Memories of Heidelberg"Auf die Produktivität von Heinz Strunk ist Verlass: Er gehört inzwischen zu den Autoren, von denen in kurzen Abständen immer wieder etwas Neues erscheint. Jedes Jahr bringt er ein weiteres Buch heraus. Mit "Der goldene Handschuh" und "Zauberberg 2" gab er selbst der wahren Geschichte um den Hamburger Frauenmörder Fritz Honka oder Thomas Manns großem Literaturklassiker die unverkennbare Strunk-Note. In seinem neuen Roman kehrt er zurück in die Trostlosigkeit des banalen Alltags. Juliane Bergmann hat "Memories of Heidelberg" gelesen.Jörg Schieke: "Chin-chin, der Weg führt ins Mondgestein"Zwischen Phantastik und Alltag, Trinkspruch und Mondgestein oszilliert der neue Band des Lyrikers und Journalisten Jörg Schieke. Im Gespräch erzählt er, wie Themen auf ihn zukommen, wie er die Diskrepanz zwischen Dichter und Literaturkritiker aushält und er liest eines seiner neuen Gedichte. "Die Summe seiner Teile" Die Graphic Novel von Julia Zejn und Matthias Lehmann kommt aus Leipzig, einer Stadt mit großer grafischer Tradition. Und hier arbeitet inzwischen auch eine junge Generation von Comic-Künstlern. Mitunter sogar zusammen. Wolfgang Schilling stellt die neue Graphic Novel vor. Patricia Thoma: Comic im GefängnisZwei Jahre lang ist Comic-Illustratorin Patricia Thoma durch verschiedene Gefängnisse in ganz Deutschland gefahren und hat Comic-Workshops für Inhaftierte gegeben. Daraus sind zwei Comic-Bände entstanden: Erst "Im Jugendarrest" und vor kurzem "Im Gefängnis". Die Zeichnungen der Inhaftierten sind in die Bücher eingeflossen. Besucht hat Thoma auch das Gefängnis "Roter Ochse" in Halle an der Saale. Tini von Poser hat Illustratorin Patricia Thoma getroffen sowie mit einem Inhaftierten in Halle gesprochen, der am Comic-Workshop teilgenommen hat. Douglas Stuart: "John of John"Cal ist zurück und all das, vor dem er nach Edinburgh geflüchtet war, ist wieder da: das karge Leben auf den Hebriden, der windgepeitschte Kreislauf aus Schafzucht und Nächten am Webstuhl, die Enge der Inselgemeinschaft. Das größte Problem ist allerdings sein Vater. Rainer Moritz stellt den Roman vor.Hörspieltipp: "Unser Haus mit Rutsche"So heißt der aktuelle Roman von Safia al Bagdadi, der jetzt auch als Hörbuch in ARD Sounds verfügbar ist. Aufgenommen wurde das Hörbuch, gesprochen von der Autorin selbst, als Koproduktion von HR, MDR, NDR und SR zusammen mit dem Hörbuchverlag speak low beim Saarländischen Rundfunk in Saarbrücken. Dort ist Safia Al Bagdadi geboren und aufgewachsen und die Stadt ist auch Schauplatz des Romans. Sally-Charell Delin war bei der Aufnahme dabei und hat mit der Autorin gesprochen

Nur der FCM! - Der Podcast
Auf uns! 10 Jahre FCM-Podcasts

Nur der FCM! - Der Podcast

Play Episode Listen Later Jul 21, 2026 117:18


Wir feiern Jubiläum - und zwar nicht irgendeins, sondern gleich zwei: 10 Jahre Podcasts zum 1. FC Magdeburg nämlich! Am 2. Juli 2016 erblickte die erste Folge des Nur der FCM!-Podcasts das Licht der Welt, wenig später oder kurz vorher (so genau ist das heute nicht mehr zu ermitteln) gingen auch die Kollegen vom MDR mit ihrem FCM-Format an den Start. Grund genug für uns, Daniel und Guido in unsere Jubiläums-Sonderfolge einzuladen und gemeinsam darüber zu sprechen, was 10 Jahre Podcasts zu einem Verein eigentlich mit einem machen, wie sich die Medienlandschaft in der Zeit verändert hat, was besondere Momente waren, die ohne den Podcast vielleicht nicht stattgefunden hätten, wie es in und mit beiden Formaten weitergeht und vieles mehr. In unser reguläres Saisonformat starten wir am 29. Juli 2026 mit Ausgabe 407.

Risky Business
Soap Box: Using threat hunting to drive detection

Risky Business

Play Episode Listen Later Jul 8, 2026 35:16


In this wholly sponsored Soap Box edition of the podcast Patrick Gray chats with Damien Lewke, the CEO and founder of Nebulock, about the future of threat hunting and detection. Damien spent a decade in the EDR and MDR space before founding Nebulock in 2024. It started off as an AI-powered threat hunt platform but has evolved into a broader security data platform that can answer questions, drive hunts and drive detections. This product is engineered around the idea that a lot of security is a data problem. So, if we accept this premise, how do we solve security? And how much of that solution is about agents, vs building a good graph? And if you're going to build a good graph, do you want to build it for a person to use, or an agent to use? This is truly a conversation for the security nerd's nerd. Enjoy! This episode is also available on YouTube Show notes

FIGARINO Geschichten
Glühwürmchen in Radlerhose

FIGARINO Geschichten

Play Episode Listen Later Jul 8, 2026 28:25


Ein Sommergewitter verhagelt Figarino und Kater Long John die Freude auf eine Nachtwanderung. Da haben sie extra so lange gewartet, um rauszugehen und dann das! Denn: Nur kurze Zeit im Jahr – meist ab der Johannisnacht im Juni bis Juli/August – kann man mit etwas Glück ab Einbruch der Dunkelheit bis um Mitternacht herum auf Wiesen und Büschen, an Waldrändern und auch da, wo es schön feucht ist, wie an Teichen oder Flussufern das magische Leuchten der Glühwürmchen entdecken.Vom Regen wollen sich Figarino und sein Freund Long John ihr Vorhaben aber nicht verderben lassen. Sie schlotzen sich ins Internet, um dort nach den Leuchtkäfern zu suchen. In der digitalen Welt hineingesaugt, stoßen sie auf ein anders leuchtendes Würmchen. Warum dort eine grell-grüne Radlerhose zum Einsatz kommt, hört selbst!Während der Fahrradschrauber und sein Kater im Internet ein ganz spezielles Abenteuer erleben, nimmt euch Reporterin Laura mit in den Saalekreis auf Glühwürmchentour. Übrigens, die Tiere besitzen einen Leuchtstoff, der dieses bezaubernde Glühen erzeugt und zwar am Popo! Das Hinterteil des Glühwürmchens besitzt eine durchsichtige Haut, die Licht hindurchscheinen lässt. Raschid Daniel Sidgi als Figarino und sein Piratenkater Kater Long John SilverAutorin: Franziska Opitz KarkTon und technische Realisierung: Holger KliemchenReporterin Laura BehlingVerantwortliche Redakteurin: Sandra M. Hänel Geeignet für Kinder ab 8 Jahre

Prolonged Fieldcare Podcast
286: Antibiotic Resistance - Smart Stewardship in Austere Care

Prolonged Fieldcare Podcast

Play Episode Listen Later Jul 6, 2026 38:52


In this episode of the Prolonged Field Care Podcast, Dennis talks with Dr. Ryan Maves (infectious disease physician and retired military ID doc) about one of the biggest silent threats in modern combat casualty care: antimicrobial resistance.From the Acinetobacter outbreaks that hit U.S. forces in Iraq and Afghanistan to the even more extreme resistance patterns Ukrainian forces are facing today, Ryan breaks down what actually works (and what doesn't) when you're managing infections in truly austere environments. They cover the landmark TDOS study, why early broad-spectrum antibiotics at the point of injury often create more problems downstream, the practical field choices between cefazolin (Ancef) and ceftriaxone, exact timing for antibiotics in sepsis, push-dose administration hacks, and why “the knife is frequently the best antibiotic.”Ryan also explains that older drugs like doxycycline and minocycline still crush certain resistant organisms and drops the single most important intervention any medic can make to slow resistance.Whether you're a combat medic, flight medic, or just serious about prolonged field care, this episode delivers immediately usable knowledge.Key Takeaways:Broad-spectrum antibiotics (like ertapenem) at the point of injury do not improve outcomes and can drive more resistance later (TDOS data).For penetrating trauma prophylaxis: Cefazolin (Ancef) remains first-line. Ceftriaxone is the best field-friendly balance when you need something a bit broader.Septic shock = antibiotics within 1 hour. Hemodynamically stable but infected = up to 3 hours.Most beta-lactams (ceftriaxone, cefazolin) can be given as rapid IV push — ideal for the field.If the patient isn't clearly improving by 72 hours, stop reflexively adding more antibiotics and aggressively hunt for source control.The single highest-impact thing you can do: meticulous hand hygiene + early, high-quality wound care/debridement. It beats any antibiotic regimen.Old drugs (doxycycline, minocycline) still have real utility against certain MDR organisms when newer agents aren't available.Listen now and upgrade how you think about infection prevention and antibiotic use in prolonged field care.Chapters:00:00 – Welcome & Why Antimicrobial Resistance Should Scare Every Field Medic02:45 – The History of AMR: From Penicillin to Modern Superbugs05:10 – Acinetobacter in Iraq/Afghanistan: The USNS Comfort Story & TDOS Study09:40 – ESKAPE Pathogens & Why Ukraine's Resistance Problem is Next-Level13:20 – The Field Reality: No Microbiology Labs, No Easy Answers16:00 – Rethinking Prophylaxis: Why Narrower Spectrum (Ancef/Ceftriaxone) Often Wins19:30 – Wound Care in Austere Settings: Chlorhexidine vs Soap & Water vs Betadine23:10 – Post-Procedure Cleaning: Chest Tubes, Crikes, and Lines25:40 – Timing of Antibiotics: The 1-Hour Rule for Septic Shock28:20 – Push-Dose Beta-Lactams: Practical Administration in the Field31:00 – When the Patient Isn't Improving: Source Control & the 72-Hour Rule34:30 – Old Drugs That Still Work: Doxycycline, Minocycline & Linezolid37:50 – The #1 Thing That Actually Moves the Needle: Hand Hygiene & Infection Prevention39:40 – Final Thoughts & ResourcesFor more content, go to ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠www.prolongedfieldcare.org⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Consider supporting us: ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠patreon.com/ProlongedFieldCareCollective⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠ or ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠www.lobocoffeeco.com/product-page/prolonged-field-care⁠⁠

Alles Geschichte - History von radioWissen
WENN DER OPA SS-MANN WAR - Marc Baumgart über NS-Täterforschung

Alles Geschichte - History von radioWissen

Play Episode Listen Later Jul 3, 2026 27:19


"Reden ist Silber, Schweigen ist Gold" - das war eine der Lebensweisheiten von Karl Baumgart, die er an seinen Enkel Marc Baumgart weitergab. Was sich konkret hinter diesem Spruch verbarg, stellte sich erst nach dem Tod der aus Sachsen stammenden Großeltern heraus, als Marc Baumgart in deren Nachlass eine Reihe Fotos fand. Aufgenommen in ihrem zeitweiligen Zuhause, einer SS-Siedlung gleich neben dem Konzentrationslager Mauthausen. Stefan Nölke (MDR) spricht mit Marc Baumgart, der mit seiner Stiftung die NS-Täter- und Täterinnenforschung fördert. Eine Gastfolge der MDR-Reihe "Diskurs" bei "Alles Geschichte".

FIGARINO Geschichten
Figarinos Fahrradladen – Die Tour

FIGARINO Geschichten

Play Episode Listen Later Jul 3, 2026 2:12


Das wohl größte Kinderspektakel des Jahres für alle Fans des "Fahrradladens“ steht in den Startlöchern: Figarino und sein sprechender Kater Long John Silver gehen auf Tour. Sie bringen "Das megamagische Zauberbuch-Brimbamborium“ mit. Was das ist? Findet es heraus und macht euch bereit für ein Show-Abenteuer, das euch zum Staunen bringen wird!Hinter den Kulissen flüstert man sich schon die wildesten Gerüchte zu. Es gibt nämlich noch geheime Gäste auf dieser Reise. Wer das ist? Das verraten wir noch nicht! Dieses große Rätsel müsst ihr selbst lösen und vor Ort entdecken.Sichert euch deshalb jetzt die Tickets für "Figarinos Fahrradladen – Die Tour“: Ihr bekommt sie direkt hier https://contracreate.com/ oder an allen bekannten Vorverkaufsstellen. Seid schnell, schnappt euch die besten Plätze für die ganze Familie!Das sind die Termine:11.10.2026 Leipzig Kupfersaal18.10.2026 Dresden Filmtheater Schauburg01.11.2026 Berlin Colosseum Berlin29.11.2026 Erfurt GEWERKSCHAFTSHAUS 23.01.2027 Köln COMEDIA Theater Köln

FIGARINO Geschichten
Frau Muschelknauz kriegt Punkte

FIGARINO Geschichten

Play Episode Listen Later Jul 1, 2026 27:39


Frau Muschelknauz sitzt aufgelöst auf dem Fußweg. Sie hat nur drei Punkte ergattert und ist somit durch ihre Französischprüfung gerasselt. Da der Kurs ein Geschenk von Frau Spardbrod für die bevorstehende gemeinsame Paris-Reise war, traut sie sich nun nicht nach Hause. Die Freunde in der Fahrradwerkstatt versuchen, sie aufzumuntern und zu trösten. Es hilft nur nichts! Frau Muschelknauz schämt sich zu sehr und will deshalb nicht mehr zurück, sondern dauerhaft im Fahrradladen einziehen! Während Kater Long John nach einer Lösung sucht, reisen wir mit Reporter Ben einmal rund um den Globus zu den Schulen dieser Welt: Dabei erfahren wir, warum sich die Kinder und Jugendlichen in England über eine Neun auf dem Zeugnis freuen. Wir checken außerdem, warum in Brasilien das Schuljahr zum Weihnachtsfest im Dezember endet und feiern mit den Kindern in Schweden das traditionelle "Skolavslutning". Und wie sieht es bei uns in Mitteldeutschland aus? An diesem Freitag erhalten viele Tausende Schülerinnen und Schüler in Sachsen, Sachsen-Anhalt und Thüringen ihre Schulzeugnisse. Wem dies Sorgen bereitet, kann bei den Beratungsangeboten von "Nummer gegen Kummer" darüber sprechen. Kinder und Jugendliche erhalten montags bis samstags von 14 bis 20 Uhr kostenfrei unter der Rufnummer 116 111 Unterstützung oder rund um die Uhr über die Online-Beratung unter www.nummergegenkummer.deAutorin: Franziska Opitz Kark Ton und technische Realisierung: Holger Kliemchen Reporter: Ben Garit Hernandez Verantwortliche Redakteurin: Sandra M. Hänel In den Rollen: Raschid Daniel Sidgi als Figarino und sein Piratenkater Kater Long John Silver Corinna Waldbauer als Frau Muschelknauz Geeignet für Kinder ab 8 Jahre

聽天下:天下雜誌Podcast
【邁向世界的破風者Ep.7】「突破歐美大廠壟斷」聯合骨材如何讓台灣骨科醫材賣進全球52國?

聽天下:天下雜誌Podcast

Play Episode Listen Later Jun 26, 2026 29:56


「曾經,在全球高階人工關節市場,台灣幾乎是沒有聲音的存在。」 面對歐美大廠的長期壟斷,聯合骨材董事長林延生與總經理林德堅認為,台灣醫材產業正走入一個憑藉高階技術立足國際的新時代。 本集《邁向世界的破風者》邀請深耕業界30餘年的聯合骨材領導團隊,分享這家隱形冠軍如何默默扎根專業,成功將產品打入全球52個國家。解析聯合骨材如何透過自主研發與品質創新,拿下「全亞洲第一張歐盟三類高風險醫材 MDR 證書」,並深入探討台灣在發展高階醫材時,如何運用生技技術優勢,突破歐美巨頭與國際法規的雙重挑戰。這是一堂為領導者準備的企業全球化課,也為新一代生醫人才指明了創新與認證下的前進方向。 主持人: 詹慶齡 來賓: 聯合骨材創辦人暨董事長 林延生、總經理 林德堅 製作團隊: 天下實驗室、天下整合傳播部 -- Hosting provided by SoundOn

M.D.R, le podcast sur la vingtaine
Ce que j'ai appris dans le monde professionnel en dix ans...

M.D.R, le podcast sur la vingtaine

Play Episode Listen Later Jun 21, 2026 18:52


Stage d'immersion, choix des bons environnements de travail, négociation salariale, lecture de contrat, etc. Dans cet épisode, je vous en parle de tout ce que j'ai appris dans le monde professionnel afin que vous ne fassiez pas les mêmes erreurs que moi. Et vous, qu'auriez-vous aimé savoir plus tôt ? Alors, prêts à me suivre pour cette saison finale de MDR, ce compte à rebours spécial vers ma trentaine ? Bienvenue dans cette ultime aventure et merci d'être là !

M.D.R, le podcast sur la vingtaine
Parlons de santé mentale et de résilience

M.D.R, le podcast sur la vingtaine

Play Episode Listen Later Jun 21, 2026 14:53


Dans mon adolescence et dans ma vingtaine, j'ai vécu beaucoup d'épisodes dépressifs et de crises d'anxiété. Il m'a fallu consulter des professionnels, construire et consolider ma résilience ainsi qu'apprendre à être plus spirituelle pour enfin voir le bout du tunnel. Cet épisode est donc un message d'espoir adressé à tous ceux qui vont mal : il y a de l'espoir ! You can get better ! Alors, prêts à me suivre pour cette saison finale de MDR, ce compte à rebours spécial vers ma trentaine ? Bienvenue dans cette ultime aventure et merci d'être là !

M.D.R, le podcast sur la vingtaine
Amitiés, support sytem, échecs, comparaisons...

M.D.R, le podcast sur la vingtaine

Play Episode Listen Later Jun 21, 2026 20:43


Dans ma vingtaine, je me suis rendu compte que l'un des plus beaux cadeaux que la vie puisse nous faire, ce sont des amitiés vraies, sincères et utiles. Et qu'en retour, la plus belle façon de montrer notre appréciation pour ces amitiés, c'était de les consolider, de les protéger et de leur accorder de la valeur dans les moments d'épreuves. Je vous en parle dans cet épisode. Alors, prêts à me suivre pour cette saison finale de MDR, ce compte à rebours spécial vers ma trentaine ? Bienvenue dans cette ultime aventure et merci d'être là !

The CyberWire
Peeling back Banana RAT. [Research Saturday]

The CyberWire

Play Episode Listen Later Jun 20, 2026 28:59


This week, we are joined by Tom Kellermann, Trend Micro's VP of AI Security and Threat Research, discussing their work on "Inside SHADOW-WATER-063's Banana RAT: From Build Server to Banking Fraud." Researchers from Trend Micro's MDR team uncovered the full operation behind Banana RAT, a sophisticated banking trojan they track as SHADOW-WATER-063, by analyzing both attacker infrastructure and infected victim systems. The malware uses fileless PowerShell execution, layered obfuscation, and remote-control capabilities to steal credentials, manipulate banking sessions, intercept Pix QR code payments, and facilitate financial fraud targeting Brazilian banks. The campaign appears to be operated by a Brazilian Portuguese-speaking cybercriminal group with ties to the broader Tetrade banking malware ecosystem and may be evolving toward a malware-as-a-service model. The research and executive brief can be found here: ⁠Inside SHADOW-WATER-063's Banana RAT: From Build Server to Banking Fraud Learn more about your ad choices. Visit megaphone.fm/adchoices

Research Saturday
Peeling back Banana RAT.

Research Saturday

Play Episode Listen Later Jun 20, 2026 28:59


This week, we are joined by Tom Kellermann, Trend Micro's VP of AI Security and Threat Research, discussing their work on "Inside SHADOW-WATER-063's Banana RAT: From Build Server to Banking Fraud." Researchers from Trend Micro's MDR team uncovered the full operation behind Banana RAT, a sophisticated banking trojan they track as SHADOW-WATER-063, by analyzing both attacker infrastructure and infected victim systems. The malware uses fileless PowerShell execution, layered obfuscation, and remote-control capabilities to steal credentials, manipulate banking sessions, intercept Pix QR code payments, and facilitate financial fraud targeting Brazilian banks. The campaign appears to be operated by a Brazilian Portuguese-speaking cybercriminal group with ties to the broader Tetrade banking malware ecosystem and may be evolving toward a malware-as-a-service model. The research and executive brief can be found here: ⁠Inside SHADOW-WATER-063's Banana RAT: From Build Server to Banking Fraud Learn more about your ad choices. Visit megaphone.fm/adchoices

Business of Tech
Vendor Outcomes, Warranties, and the Shift from Risk Manager to Delivery Arm for MSPs

Business of Tech

Play Episode Listen Later Jun 3, 2026 13:03


Outcome-based managed security and attached vendor warranties are driving a new form of coverage-based vendor lock-in for MSPs and IT service providers. Vendors such as Intezer and SPECTRA are introducing performance guarantees, SLAs, and cyber resilience warranties that require MSPs to fully standardize on their architectures. This evolving model shifts accountability for enforcement and risk management from the individual MSP to the vendor's operating model, thereby altering the independent role of the MSP within client environments. A notable example is Intezer's Amplify Partner program, which asserts that its platform can process 100% of security alerts while escalating fewer than 2% for human review—claims the company frames as outcomes rather than product specifications. SPECTRA's use of certification-linked warranties, distributed via Ingram Micro, establishes channel-distributable assurance products with explicit conditions attached at every level. According to a Check Point report, while 77% of organizations report having adopted AI for cloud security, only 26% feel capable of enforcing those strategies, revealing a gap between security intent and operational ability. This structural shift is further illustrated by Merlin Cyber's FedRAMP managed service offering, Lumen's MDR enhancements targeting mid-market MSPs, and Trustlogix's addition of intent-based authorization controls. The FBI's announcement regarding Microsoft 365 OAuth token hijacking and recent vulnerabilities in widely used platforms like ConnectWise Automate underscore the real-world risks of automation platforms being targeted. These developments collectively point to growing operational complexity, rising compliance burdens, and the need for MSPs to separate their commitments from upstream vendor claims. For operators, the trend demands increased scrutiny of warranty terms, claim denial conditions, and SLA language before making any client-facing assurances. MSPs risk absorbing liability if they repeat vendor marketing claims without contractual clarity or operational control. Effective governance now requires independently produced, audit-ready evidence that documents compliance and enforcement separate from vendor portals. As assurance sales proliferate, the operational gap between acting as an underwriter versus a reseller will drive market differentiation, affecting both pricing structures and eligibility for vendor-backed coverage. 00:00 Channel-Ready Security 03:41 Policy vs. Reality 05:59 MFA Isn't Enough 09:12 Why Do We Care?    Supported by:  ScalePad Moovila   

Lehman Ave Church of Christ
Equipped 2026: "From the Beginning God" by Dan Winkler - Part 3

Lehman Ave Church of Christ

Play Episode Listen Later May 31, 2026 47:05


April 26, 2026 - Equipped 2026 - Day 4 - 8:30 AM Session   Dan Winkler continues a series centered on the phrase “from the beginning,” which occurs 23 times in the New Testament. This session examines Matthew 19, where the phrase appears twice in the context of marriage, divorce, and remarriage (MDR). The speaker critiques common misreadings of the chapter, stressing that its broader theme is “kingdom living,” and that isolating verse 9 neglects crucial context. The lecture unpacks Matthew 19:1-12: the Pharisees' test question on divorce, Jesus' answer anchoring marriage in God's original intent at creation, and the dialogue on the certificate of divorce and eunuchs for the kingdom's sake. A thorough analysis of Matthew 19:9 defines “whoever,” “divorce,” and “adultery,” arguing that God's marriage law applies to all people, not only those in covenant with Him. The session ends with practical lessons for strengthening marriage: using Scripture as the guide, following God's pattern of leaving and cleaving, cultivating togetherness, tender-heartedness, and prioritizing the kingdom of God. Duration 47:05

Faces of Digital Health
Doctors are using ChatGPT in clinic and not all care about privacy (Health.Tech 2026)

Faces of Digital Health

Play Episode Listen Later May 26, 2026 42:40


Doctors are using ChatGPT in clinic right now — and some of them don't care about privacy. Three operators on what that means for healthcare AI. Recorded live at health.tech in Basel, this panel from Faces of Digital Health unpacks the convergence reshaping clinical software: ambient AI scribes, agentic AI in healthcare, on-device LLMs, and the regulatory drag (MDR, EU AI Act, EHDS) that is widening the gap between what clinicians actually use and what hospitals are allowed to buy. Host Tjaša Zajc is joined by: Jonathan Bringas — CEO & Founder, Lapsi Health (Kaiku: FDA-cleared AI stethoscope, ambient scribe and clinical assistant in one device) Blaž Triglav — CEO, Mediately (drug information platform, 1M+ HCPs across Europe) Amanda Herbrand — Clinical data modelling consultant, formerly University Hospital Basel What the conversation covers: — Why EHR data fragmentation is the precondition AI hasn't solved — Shadow AI: why clinicians trust ChatGPT more than enterprise tools (and the agency hypothesis behind it) — The convergence of stethoscopes, scribes, drug information and decision support into one workflow layer — ROI in healthcare AI: financial, time, clinical accuracy — and Herbrand's fourth dimension, user satisfaction — "Doctors were the original vibe coders": the 2,000 Excel spreadsheets running European hospitals — Why FDA-cleared beats MDR in 2026 sales cycles, and what Chile's regulatory minimalism tells us — The asymmetry that will break European medtech: applicants using AI to build, regulators forbidden from using AI to assess — On-device AI, ambient computing, AGI in clinical workflows — and the de-skilling risk no one wants to discuss ⏱ Chapters 00:00 — Opening: AI agents, vibe coding, and what doctors actually want 01:30 — Data fragmentation: the precondition AI hasn't solved (Amanda Herbrand) 02:30 — Keiku: collapsing stethoscope, scribe and assistant into one device 05:15 — The convergence reshaping healthcare AI — and the shadow AI in clinic 07:30 — Why doctors trust ChatGPT more than enterprise tools: the agency hypothesis 10:30 — ROI: financial, time, clinical accuracy — and Herbrand's fourth dimension 15:30 — Choosing solutions: modular requirements and FDA-cleared moats 19:30 — EHDS and the missing connector in European standardisation 21:00 — "Doctors were the original vibe coders": the 2,000 spreadsheet problem 24:30 — The two-speed world: regulated medicine vs the Wild West 28:00 — Why Chile's regulatory minimalism beats Europe's MDR 30:30 — Agentic AI vs regulators: the asymmetry that will break European medtech 33:30 — On-device AI, AGI, and the deskilling no one wants to discuss

Paul's Security Weekly
Visibility with EDR/MDR is still important, 'the basics' are impossible, and the news - Rob Allen - ESW #460

Paul's Security Weekly

Play Episode Listen Later May 25, 2026 104:54


Interview with Rob Allen from Threatlocker This week, Rob Allen from Threatlocker is with us to discuss the importance of EDR and MDR visibility. We discuss some real world attacks and anecdotes where EDR was able to save the day when threats were missed by other controls. Topic: Do the basics, they said. Easier said than done. Guillaume and Adrian discuss the futility of attempting to do all the foundational work standards, best practices, and regulations expect of organizations. Adrian has given up. Fortunately, Guillaume has some excellent advice and hope to share on this front. The weekly enterprise news Finally, in the enterprise security news, a really interesting vibe check funding acquisitions the verizon DBIR we give a tutorial on how to leak AWS keys on github OH NEVERMIND, SOMEONE AT CISA ALREADY MADE THE TUTORIAL agents versus agents exploitbench the vulnpocalypse robot dogs are SO EASY to take out, we don't need to be too scared of them yet All that and more, on this episode of Enterprise Security Weekly. Visit https://www.securityweekly.com/esw for all the latest episodes! Show Notes: https://securityweekly.com/esw-460

Enterprise Security Weekly (Audio)
Visibility with EDR/MDR is still important, 'the basics' are impossible, and the news - Rob Allen - ESW #460

Enterprise Security Weekly (Audio)

Play Episode Listen Later May 25, 2026 104:54


Interview with Rob Allen from Threatlocker This week, Rob Allen from Threatlocker is with us to discuss the importance of EDR and MDR visibility. We discuss some real world attacks and anecdotes where EDR was able to save the day when threats were missed by other controls. Topic: Do the basics, they said. Easier said than done. Guillaume and Adrian discuss the futility of attempting to do all the foundational work standards, best practices, and regulations expect of organizations. Adrian has given up. Fortunately, Guillaume has some excellent advice and hope to share on this front. The weekly enterprise news Finally, in the enterprise security news, a really interesting vibe check funding acquisitions the verizon DBIR we give a tutorial on how to leak AWS keys on github OH NEVERMIND, SOMEONE AT CISA ALREADY MADE THE TUTORIAL agents versus agents exploitbench the vulnpocalypse robot dogs are SO EASY to take out, we don't need to be too scared of them yet All that and more, on this episode of Enterprise Security Weekly. Visit https://www.securityweekly.com/esw for all the latest episodes! Show Notes: https://securityweekly.com/esw-460

Paul's Security Weekly TV
Visibility with EDR/MDR is still important, 'the basics' are impossible, and the news - Rob Allen - ESW #460

Paul's Security Weekly TV

Play Episode Listen Later May 25, 2026 104:54


Interview with Rob Allen from Threatlocker This week, Rob Allen from Threatlocker is with us to discuss the importance of EDR and MDR visibility. We discuss some real world attacks and anecdotes where EDR was able to save the day when threats were missed by other controls. Topic: Do the basics, they said. Easier said than done. Guillaume and Adrian discuss the futility of attempting to do all the foundational work standards, best practices, and regulations expect of organizations. Adrian has given up. Fortunately, Guillaume has some excellent advice and hope to share on this front. The weekly enterprise news Finally, in the enterprise security news, a really interesting vibe check funding acquisitions the verizon DBIR we give a tutorial on how to leak AWS keys on github OH NEVERMIND, SOMEONE AT CISA ALREADY MADE THE TUTORIAL agents versus agents exploitbench the vulnpocalypse robot dogs are SO EASY to take out, we don't need to be too scared of them yet All that and more, on this episode of Enterprise Security Weekly. Show Notes: https://securityweekly.com/esw-460

Enterprise Security Weekly (Video)
Visibility with EDR/MDR is still important, 'the basics' are impossible, and the news - Rob Allen - ESW #460

Enterprise Security Weekly (Video)

Play Episode Listen Later May 25, 2026 104:54


Interview with Rob Allen from Threatlocker This week, Rob Allen from Threatlocker is with us to discuss the importance of EDR and MDR visibility. We discuss some real world attacks and anecdotes where EDR was able to save the day when threats were missed by other controls. Topic: Do the basics, they said. Easier said than done. Guillaume and Adrian discuss the futility of attempting to do all the foundational work standards, best practices, and regulations expect of organizations. Adrian has given up. Fortunately, Guillaume has some excellent advice and hope to share on this front. The weekly enterprise news Finally, in the enterprise security news, a really interesting vibe check funding acquisitions the verizon DBIR we give a tutorial on how to leak AWS keys on github OH NEVERMIND, SOMEONE AT CISA ALREADY MADE THE TUTORIAL agents versus agents exploitbench the vulnpocalypse robot dogs are SO EASY to take out, we don't need to be too scared of them yet All that and more, on this episode of Enterprise Security Weekly. Show Notes: https://securityweekly.com/esw-460

ITSPmagazine | Technology. Cybersecurity. Society
After RSAC Conference 2026, Reflecting on Agentic AI, Community, and the Evolution of Cybersecurity | A Brand Highlight at RSAC Conference 2026 with Tony Anscombe, Chief Security Evangelist of ESET

ITSPmagazine | Technology. Cybersecurity. Society

Play Episode Listen Later May 23, 2026 7:33


Agentic AI was the theme that pulled away from the pack at RSAC Conference 2026. Tony Anscombe of ESET makes the case that once AI shifts from being directed by humans to operating with its own objectives and logic, the security surface changes with it, and organizations are being forced to rethink what they protect and how. At the show, ESET announced two products that meet that moment head on. The ESET AI Skills Checker is a free-to-use tool coming to market. ESET AI Protection looks inside AI sessions on the endpoint, flagging sensitive data leakage, malicious links returned by AI systems, and suspicious behavior, and surfacing it all inside normal cybersecurity operations for investigation, blocking, or detection. Tony closes with a reminder worth keeping. His first RSA was in 1998, and the technology he worked on then (sandboxing, dynamic code, remote windowing, encryption, authentication) mirrors a lot of what walks the RSAC Conference floor today. The packaging evolves, the core principles do not. Build forward, but do not lose sight of what the past already proved. This is a Brand Highlight. A Brand Highlight is a ~5 minute introductory conversation designed to put a spotlight on the guest and their company. Learn more: https://www.studioc60.com/creation#highlight GUEST Tony Anscombe, Chief Security Evangelist, ESET LinkedIn: https://www.linkedin.com/in/tonyanscombe/ RESOURCES Learn more about ESET: https://www.eset.com ESET AI Skills Checker and ESET AI Protection: https://www.eset.com Are you interested in telling your story? ▶︎ Full Length Brand Story: https://www.studioc60.com/content-creation#full ▶︎ Brand Spotlight Story: https://www.studioc60.com/content-creation#spotlight ▶︎ Brand Highlight Story: https://www.studioc60.com/content-creation#highlight KEYWORDS Tony Anscombe, ESET, Sean Martin, brand story, brand marketing, marketing podcast, brand highlight, agentic AI, AI security, RSAC Conference 2026, threat intelligence, MDR, EDR, endpoint security, AI Skills Checker, AI Protection, cybersecurity community, multifactor authentication, cybersecurity evolution Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.

Medical Device made Easy Podcast
How can a proper Intended Use save your device?

Medical Device made Easy Podcast

Play Episode Listen Later May 21, 2026 33:24


A medical device's intended use is not just a regulatory formality — it is the foundation of the entire product strategy.In this podcast episode, Monir El Azzouzi speaks with Karandeep Badwal about how intended use influences classification, clinical evaluation, risk management, labeling, and ultimately market access.The discussion explores why many companies underestimate the importance of intended use and how poorly written statements can create major downstream regulatory problems. From Software as a Medical Device (SaMD) to AI-driven products, the episode highlights real-world examples where unclear intended use created challenges during certification and compliance activities.The episode also provides practical guidance for manufacturers on:Defining a robust intended use statementAligning intended use with clinical evidence and risk managementAvoiding “labeling tricks” that may trigger regulatory scrutinyBuilding internal collaboration between regulatory, clinical, and product teamsThis is an essential discussion for MedTech startups, QA/RA professionals, and manufacturers navigating MDR, IVDR, FDA, or global regulatory pathways.Who is Monir El Azzouzi? Monir El Azzouzi is the founder and CEO of Easy Medical Device a Consulting firm that is supporting Medical Device manufacturers for any Quality and Regulatory affairs activities all over the world. Monir can help you to create your Quality Management System, Technical Documentation or he can also take care of your Clinical Evaluation, Clinical Investigation through his team or partners. Easy Medical Device can also become your Authorized Representative and Independent Importer Service provider for EU, UK and Switzerland. Monir has around 16 years of experience within the Medical Device industry working for small businesses and also big corporate companies. He has now supported around 100 clients to remain compliant on the market. His passion to the Medical Device filed pushed him to create educative contents like, blog, podcast, YouTube videos, LinkedIn Lives where he invites guests who are sharing educative information to his audience. Visit easymedicaldevice.com to know more.  If you need help implementing QMSR or preparing your teams for FDA inspections, contact: info@easymedicaldevice.com If you are located outside the EU/UK/Switzerland and need an Authorized Representative (and possibly an Importer), we can support you as well.Linkkarandeepbadwal linkedin: https://www.linkedin.com/in/karandeepbadwal/qra-medical linkedin: https://www.linkedin.com/company/qra-medical/Social Media to followMonir El Azzouzi Linkedin: https://linkedin.com/in/melazzouziTwitter: https://twitter.com/elazzouzimPinterest: https://www.pinterest.com/easymedicaldeviceInstagram: https://www.instagram.com/easymedicaldeviceThis podcast is hosted by Podcastics, the easiest platform to create and publish your podcast.

House Podcastica: A Game of Thrones Podcast
Severance S2E4 "Woe's Hollow"

House Podcastica: A Game of Thrones Podcast

Play Episode Listen Later May 15, 2026 106:44


Reposted from Wax Episodic, which you can find at: https://podcastica.com/podcast/wax-episodic — Interesting how with just a simple change of scenery, all the weirdness of this show just kind of disappears. Just kidding, MDR's excursion to the wintery and bleakly beautiful Woe's Hollow was weird as fuck, and we wouldn't want it any other way. We're delighted to be joined this episode by Rachel, who's been granted provisional access to this audio experience. Please enjoy her insights equally.  Mentioned: Pluribus — Carol's Trip Bonus Scene: https://www.youtube.com/watch?v=bYmiqh7-Fnw&t=24s   Next up on Severance: S2E5 “Trojan's Horse”. Let us know your thoughts! You can email or send a voice message to waffleparty@podcastica.com. Or join our Discord where you can leave comments and chat with hosts and other listeners: https://discord.gg/6WUMt3m3qe  Or check out our Podcastica Facebook group, where we put up comment posts for each episode, at facebook.com/groups/podcastica. Show support and get ad-free episodes and a bunch of other cool stuff: patreon.com/jasoncabassi  Or go to buymeacoffee.com/cabassi for a one-time donation. Come join our Discord and chat with hosts and other listeners:  Don't know what Discord is? It's kind of like a chat forum, our own little private Podcastica space to talk about Severance, Pluribus, Fallout, Welcome to Derry, Alien: Earth, and whatever else we want. It's free, and it's fun. Invitation link: https://discord.gg/6WUMt3m3qe  Other shows we cover on this podcast: We cover these other intelligent, engaging, oftentimes delightfully twisted shows: Fallout (Amazon): A crazy retro-futuristic post-apocalyptic melange of wholesomeness and depravity. One of the best looking shows on TV, funny as hell, violent AF (but in a cartoony way), and with a great cast, including Ella Purnell (Yellowjackets) and Walton Goggins (The White Lotus, The Righteous Gemstones). Not to be missed! Hosted by Jason, Kara, and Kasi. Pluribus (Apple TV): Everyone is transformed into a pleasant hive mind — except for Carol (Rhea Seehorn), the most miserable woman on the planet, who must save the world from happiness. It's sounds weird, and it is… in the best way. Created by the great Vince Gilligan, of Breaking Bad and Better Call Saul. Hosted by Jason and Karen! IT: Welcome to Derry (HBO): A fun, scary, and surprisingly great prequel to the 2016 and 2019 IT movies, Pennywise stalks the children of 1962 Derry. A mix of heart, mystery, charm, and some shockingly disturbing Nightmare on Elme Street-esque horror. Cohosted by Shawn of Strange Indeed. Alien: Earth (FX): From the brilliant Noah Hawley (Fargo, Legion), this one really scratches that sci-fi itch. A greedy corporate tech overlord transfers the consciousness of a group of terminally ill children into highly performant synth bodies. And the Xenomorph is in it, too. Also, Tim Olyphant! Hosted by Jason, Kara, and Randy. Check out other podcasts on our network at podcastica.com.  Digging our podcast? A quick, free, and easy way to show support and help bump us up in the charts is to give us a rating or a review: On Apple Podcasts: https://podcasts.apple.com/us/podcast/wax-episodic-alien-earth/id1824392797 On Spotify: https://open.spotify.com/show/7sA66ySwVRIsdzBBdriEGV?si=87f36cd30cc54dc5  Or just search for “Wax Episodic” wherever you get podcasts.  Thank you! Learn more about your ad choices. Visit megaphone.fm/adchoices

The Cybersecurity Defenders Podcast
How AI adoption in enterprise infrastructure has expanded the attack surface with Katherine McNamara from Cisco / Defender Fridays [#318]

The Cybersecurity Defenders Podcast

Play Episode Listen Later May 4, 2026 36:15


Today on Defender Fridays, Katherine McNamara, Cybersecurity Technical Solutions Architect at Cisco, joins us to discuss how AI and ML adoption in enterprise infrastructure has expanded the attack surface for AI-driven systems.She'll walk through the security challenges unique to generative AI and ML-based architectures, and cover the four critical components: Model, Data, Application, and System, that organizations need to secure to maintain integrity.Katherine works for Cisco as a Cybersecurity Systems Engineer by day and by night, she's labbing and trying new things with the resources she has available. Katherine loves technology and getting her hands into the CLI or trying something new. She holds a Bachelors of Science and Masters of Information Security and Assurance from Western Governors University as well as several industry certifications. Register for Live SessionsJoin us every Friday at 10:30am PT for live, interactive discussions with industry experts. Whether you're a seasoned professional or just curious about the field, these sessions offer an engaging dialogue between our guests, hosts, and you – our audience.Register here: https://limacharlie.io/defender-fridaysSubscribe to our YouTube channel and hit the notification bell to never miss a live session or catch up on past episodes!Sponsored by LimaCharlieThis episode is brought to you by LimaCharlie, a cloud-native SecOps platform where AI agents operate security infrastructure directly. Founded in 2018, LimaCharlie provides complete API coverage across detection, response, automation, and telemetry, with multi-tenant architecture designed for MSSPs and MDR providers managing thousands of unique client environments.Why LimaCharlie?Transparency: Complete visibility into every action and decision. No black boxes, no vendor lock-in.Scalability: Security operations that scale like infrastructure, not like procurement cycles. Move at cloud speed.Unopinionated Design: Integrate the tools you need, not just those contracts allow. Build security on your terms.Agentic SecOps Workspace (ASW): AI agents that operate alongside your team with observable, auditable actions through the same APIs human analysts use.Security Primitives: Composable building blocks that endure as tools come and go. Build once, evolve continuously.Try the Agentic SecOps Workspace free: https://limacharlie.ioLearn more: https://docs.limacharlie.io/Follow LimaCharlieSign up for free: https://limacharlie.io/LinkedIn: / limacharlieio X: https://x.com/limacharlieioCommunity Discourse: https://community.limacharlie.com/Host: Maxime Lamothe-Brassard - CEO / Co-founder at LimaCharlie

The Cybersecurity Defenders Podcast
Real examples of AI-powered code scanning with Jeff McJunkin from Rogue Valley Information Security / Defender Fridays [#315]

The Cybersecurity Defenders Podcast

Play Episode Listen Later Apr 27, 2026 32:41


Jeff McJunkin, Founder of Rogue Valley Information Security, joins Defender Fridays to talk AI-powered code scanning for vulnerabilities. Jeff walks through real examples including using AI to find privilege escalation bugs in the Linux kernel.Jeff McJunkin is the founder of Rogue Valley Information Security, a consulting firm specializing in penetration testing and red team engagements. Jeff found the offensive side of cyber security very alluring during one the first penetration tests of his career. Feeling the challenge of host defenses like AV and centralized logging, and, at the time, knowing nothing about AV evasion or avoiding events that are likely to cause alerts, it was all very exciting. The challenge of successfully accomplishing the goal of that pen test, using essentially only native tools, was addictive for Jeff. He was hooked. Since those first penetration tests, Jeff has gone on to become an expert in the field, doing assessments for Fortune 100 companies, architecting two major versions of Core NetWars Experience, and contributing a vast amount of material to SANS Penetration Testing.Register for Live SessionsJoin us every Friday at 10:30am PT for live, interactive discussions with industry experts. Whether you're a seasoned professional or just curious about the field, these sessions offer an engaging dialogue between our guests, hosts, and you – our audience.Register here: https://limacharlie.io/defender-fridaysSubscribe to our YouTube channel and hit the notification bell to never miss a live session or catch up on past episodes!Sponsored by LimaCharlieThis episode is brought to you by LimaCharlie, a cloud-native SecOps platform where AI agents operate security infrastructure directly. Founded in 2018, LimaCharlie provides complete API coverage across detection, response, automation, and telemetry, with multi-tenant architecture designed for MSSPs and MDR providers managing thousands of unique client environments.Why LimaCharlie?Transparency: Complete visibility into every action and decision. No black boxes, no vendor lock-in.Scalability: Security operations that scale like infrastructure, not like procurement cycles. Move at cloud speed.Unopinionated Design: Integrate the tools you need, not just those contracts allow. Build security on your terms.Agentic SecOps Workspace (ASW): AI agents that operate alongside your team with observable, auditable actions through the same APIs human analysts use.Security Primitives: Composable building blocks that endure as tools come and go. Build once, evolve continuously.Try the Agentic SecOps Workspace free: https://limacharlie.ioLearn more: https://docs.limacharlie.io/Follow LimaCharlieSign up for free: https://limacharlie.io/LinkedIn: / limacharlieio X: https://x.com/limacharlieioCommunity Discourse: https://community.limacharlie.com/Host: Maxime Lamothe-Brassard - CEO / Co-founder at LimaCharlie

The Physio Matters Podcast
A Collaborative View For Industry Support - Chewing It Over with Jim Carr | Eos Active

The Physio Matters Podcast

Play Episode Listen Later Apr 19, 2026 35:47


eosactive.co.ukIn this episode of Chewing It Over, Jack speaks with Jim Carr from EOS Active about a part of MSK practice that often gets overlooked or handled poorly: the relationship between products, pathways, branding, and patient communication.Although EOS Active technically sells products into the MSK space, Jim is clear that he does not want to be seen as simply “selling injections.” Instead, he argues that products only make sense when they are nested within a wider, well-reasoned patient pathway. An injection, brace, cryotherapy device, or sleeve is not the story in itself; it is only one possible component of a longer management process shaped by rehabilitation, education, timing, and patient context.A major theme of the conversation is that clinics often inherit their marketing language from manufacturers without fully realising it. Glossy flyers, miracle-style testimonials, and product-led messaging can slowly become part of a clinic's identity, even if they do not reflect how that clinic actually wants to practise. Jim's answer is to help clinics present information in a more neutral, patient-centred way that supports trust rather than hype.The discussion also explores why Jim feels unusually aligned with private clinics. He sees parallels between building a distribution business and building a clinical service: both require strategy, long-term thinking, and careful management of brand and reputation. Rather than pushing the newest thing, he prefers established, sensible options that fit real-world practice.Overall, this episode is about thinking beyond transactions. It asks clinics to be more intentional about what they communicate, how they communicate it, and how commercial choices shape the care experience patients receive.Cingal® as a multi-joint injection is now EU MDR certified.The certification includes expanded indications for multiple synovial joints, including the knee, hip, shoulder and ankle, supporting broader clinical application.As part of the MDR transition, the manufacturer is completing the final administrative steps to ensure update IFUs and supporting documentation are available in line with regulatory requirements. Further information will be shared in due course. Eos active as te UK partner are preparing updated marterials allowing you to communicate appropriatley with patients in clinic and can answer questions and quiries about this recent update. 

The Cybersecurity Defenders Podcast
How do you know your AI agents are actually correct? With Dylan Williams from Spectrum Security / Defender Fridays [#312]

The Cybersecurity Defenders Podcast

Play Episode Listen Later Apr 17, 2026 33:26


Today, Dylan Williams, Co-Founder and Chief Research Officer at Spectrum Security, joins Defender Fridays to dig into that exact problem: self-evaluating agents, trajectory analysis, and what improvement looks like in production.Learn more at https://www.spectrum.security/Register for Live SessionsJoin us every Friday at 10:30am PT for live, interactive discussions with industry experts. Whether you're a seasoned professional or just curious about the field, these sessions offer an engaging dialogue between our guests, hosts, and you – our audience.Register here: https://limacharlie.io/defender-fridaysSubscribe to our YouTube channel and hit the notification bell to never miss a live session or catch up on past episodes!Sponsored by LimaCharlieThis episode is brought to you by LimaCharlie, a cloud-native SecOps platform where AI agents operate security infrastructure directly. Founded in 2018, LimaCharlie provides complete API coverage across detection, response, automation, and telemetry, with multi-tenant architecture designed for MSSPs and MDR providers managing thousands of unique client environments.Why LimaCharlie?Transparency: Complete visibility into every action and decision. No black boxes, no vendor lock-in.Scalability: Security operations that scale like infrastructure, not like procurement cycles. Move at cloud speed.Unopinionated Design: Integrate the tools you need, not just those contracts allow. Build security on your terms.Agentic SecOps Workspace (ASW): AI agents that operate alongside your team with observable, auditable actions through the same APIs human analysts use.Security Primitives: Composable building blocks that endure as tools come and go. Build once, evolve continuously.Try the Agentic SecOps Workspace free: https://limacharlie.ioLearn more: https://docs.limacharlie.io/Follow LimaCharlieSign up for free: https://limacharlie.io/LinkedIn: / limacharlieio X: https://x.com/limacharlieioCommunity Discourse: https://community.limacharlie.com/Host: Maxime Lamothe-Brassard - CEO / Co-founder at LimaCharlie

Business of Tech
Rich Freeman on How VC-Backed AI MSPs Like Treeline Reshape Operator Labor Needs

Business of Tech

Play Episode Listen Later Apr 16, 2026 34:11


A structural shift is underway in the managed services sector as venture capital firms move beyond traditional software and vendor investments to fund MSPs directly. This change is exemplified by investments from firms like Andreessen Horowitz, General Catalyst, and Thrive Capital into MSP-specific companies such as Treeline, Titan, and SHIELD. The driving mechanism is the perceived profit potential at the intersection of advanced AI technology and service delivery, with investors targeting AI-native operational models rather than standard rollups or inorganic growth strategies. The episode's primary evidence centers on Andreessen Horowitz's $25 million investment in Treeline, marking its entry alongside previously funded firms Titan (with $74 million from General Catalyst) and SHIELD (over $200 million from Thrive and ZBS Partners). According to Speaker A, Treeline employs proprietary AI-driven service desk automation and reports resolving 98% of help desk requests with AI, altering the economics and labor requirements for traditional MSPs. Unlike rollups, Treeline is focused on organic growth, leveraging targeted acquisitions primarily for talent rather than client base expansion. Supporting developments include the parallel strategies of Titan and SHIELD, which also integrate Silicon Valley AI expertise and homegrown tooling to drive operational efficiency. While these companies currently deploy AI internally for service automation, Treeline distinguishes itself by offering customer-facing AI-powered MDR and compliance services immediately. All three firms reflect the shift towards vertically integrated models where software, service automation, and client-facing solutions are developed and deployed in-house, creating potential competitive pressure for both traditional MSPs and larger private equity-backed consolidators. Operationally, these developments introduce risks around increased pricing pressure, labor model disruption, and a potential skills gap for MSPs reliant on off-the-shelf tooling. The focus on organic growth and deliberate scaling by new entrants like Treeline signals that the transition for incumbents is not immediate, but the need for MSPs to evaluate their AI adoption strategy is acute. Relationships alone are unlikely to differentiate providers in the long term; practical safeguards must include closing operational efficiency gaps, building internal AI capability, and considering cooperative models to maintain autonomy while reducing risk of margin erosion or client loss. Supported by: Zero NetworksCometBackup

The Cybersecurity Defenders Podcast
Levelling up your AI SOC with Joshua Neil from Alpha Level / Defender Fridays [#309]

The Cybersecurity Defenders Podcast

Play Episode Listen Later Apr 10, 2026 34:18


Joshua Neil, Co-Founder of Alpha Level, dives into a more sophisticated understanding of AI SOCs. Join the conversation about this industry change on Defender Fridays.Dr. Joshua Neil, has been a pioneer in applying machine learning to cybersecurity since 2000, starting his journey at Los Alamos National Laboratory. There, he co-developed Pathscan, a network anomaly detection system capable of spotting attacks that slip past traditional defenses. In 2014, he and CEO Mike Pozmantier took that innovation to market by licensing Pathscan to Ernst & Young (EY), turning deep research into enterprise impact.That experience exposed a hard truth: anomaly detection is powerful at catching unknown threats - but on its own, it creates too much noise. Josh went on to tackle the other half of the problem, alert overload, through leadership roles at Microsoft and Securonix, gaining firsthand insight into the real-world struggles of security teams.In 2023, Josh and Mike launched Alpha Level to bring both worlds together: pairing the depth of anomaly detection with the precision of behavioral threat signals. The result? A platform that reduces false positives, adapts to your environment, and lets teams focus on real threats—before they become breaches. Learn more here: https://alphalevel.ai/Learn more at reconinfosec.comRegister for Live SessionsJoin us every Friday at 10:30am PT for live, interactive discussions with industry experts. Whether you're a seasoned professional or just curious about the field, these sessions offer an engaging dialogue between our guests, hosts, and you – our audience.Register here: https://limacharlie.io/defender-fridaysSubscribe to our YouTube channel and hit the notification bell to never miss a live session or catch up on past episodes!Sponsored by LimaCharlieThis episode is brought to you by LimaCharlie, a cloud-native SecOps platform where AI agents operate security infrastructure directly. Founded in 2018, LimaCharlie provides complete API coverage across detection, response, automation, and telemetry, with multi-tenant architecture designed for MSSPs and MDR providers managing thousands of unique client environments.Why LimaCharlie?Transparency: Complete visibility into every action and decision. No black boxes, no vendor lock-in.Scalability: Security operations that scale like infrastructure, not like procurement cycles. Move at cloud speed.Unopinionated Design: Integrate the tools you need, not just those contracts allow. Build security on your terms.Agentic SecOps Workspace (ASW): AI agents that operate alongside your team with observable, auditable actions through the same APIs human analysts use.Security Primitives: Composable building blocks that endure as tools come and go. Build once, evolve continuously.Try the Agentic SecOps Workspace free: https://limacharlie.ioLearn more: https://docs.limacharlie.io/Follow LimaCharlieSign up for free: https://limacharlie.io/LinkedIn: / limacharlieio X: https://x.com/limacharlieioCommunity Discourse: https://community.limacharlie.com/Host: Maxime Lamothe-Brassard - CEO / Co-founder at LimaCharlie

ITSPmagazine | Technology. Cybersecurity. Society
When OT Goes Down, the Clock Is Already Running | A Brand Highlight Conversation with Rob Demain, CEO & Founder of e2e-assure | Hosted by Marco Ciappelli

ITSPmagazine | Technology. Cybersecurity. Society

Play Episode Listen Later Apr 9, 2026 6:49


When a production line stops, the financial damage is immediate — and the window to respond safely is narrower than most security teams realize. Rob Demain, CEO and Founder of e2e-assure, joins this Brand Highlight to explain why OT security demands a fundamentally different mindset than IT, and what organizations can do about it. Operational technology runs the infrastructure that keeps the world moving — manufacturing floors, power grids, air traffic control systems. Rob Demain founded e2e-assure in 2013 and has spent the past seven years narrowing its focus to one discipline: SOC and MDR services. He calls it "specificity" — the principle that doing one thing with precision delivers better outcomes than spreading resources thin. In IT security, the primary concern is data. In OT, the stakes are entirely different. Downtime is the real threat. For a manufacturing business, minutes of halted production translate directly into significant financial loss. That distinction changes everything about how security teams must respond. The "safety first" rule in OT means responders sometimes have to run alongside a threat rather than immediately neutralize it — because disconnecting systems could halt the production line entirely. The most common attack path into OT environments runs through IT: adversaries compromise IT first, then move laterally into OT systems. Supply chain risk is the second major vector. Firmware updates, software patches, and third-party management systems all represent potential entry points. Detection takes longer too — OT systems often lack the endpoint tools that trigger fast alerts, leaving threats to surface as subtle pattern deviations over extended periods. This is a Brand Highlight — a short introductory conversation designed to put a spotlight on the guest and their company. Learn more: https://www.studioc60.com/creation#highlight GUEST Rob Demain, CEO & Founder, e2e-assure LinkedIn: https://uk.linkedin.com/in/rob-demain-01733468 RESOURCES e2e-assure website: https://e2e-assure.com OT Downtime and Remediation Gaps Research: https://e2e-assure.com Are you interested in telling your story? Full Length Brand Story: https://www.studioc60.com/content-creation#full Brand Spotlight Story: https://www.studioc60.com/content-creation#spotlight Brand Highlight Story: https://www.studioc60.com/content-creation#highlight   Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.

Cloud Security Podcast by Google
EP271 Can AI-Native MDR Actually Fix Your Broken SOC Workflows or Just Automate the Mess?

Cloud Security Podcast by Google

Play Episode Listen Later Apr 9, 2026 27:29


Guests: Eric Foster, CEO, Tenex.AI Bashar Abouseido, President,  Tenex.AI Topics: "10X SOC" sounds great.  But for an organization stuck in "SIEM 1.0" with poor data quality and manual workflows, is "AI-native MDR" a "leapfrog" opportunity or a recipe for disaster? We've seen the rise of "Decoupled SIEM" and security data lakes. Does a "Modern SIEM" even need to exist if an MDR platform has an agentic layer doing the heavy lifting?  You've argued for AI-native over AI-bolted-on. For an end user, what are the tangible differences of using "AI inside a legacy SIEM" versus using an "AI-native separate product"? What is the one task you thought AI would handle by now that still requires a senior human analyst to step in? If a CISO is using an AI MDR, "Mean Time to Detect" (MTTD) starts to look like a vanity metric because the machine is instant. What is the new golden metric for an AI-powered SOC? Is it "Time to Context," "Reduction in Human Toil," or something else? How do you help a skeptical SOC Manager—who has been burned by false positives for a decade—trust an autonomous agent to perform a "containment" action at 3:00 AM?   Resources: EP227 AI-Native MDR: Betting on the Future of Security Operations? EP10 SIEM Modernization? Is That a Thing? The original "10X" paper "Autonomic Security Operations: 10X Transformation of the Security Operations Center"

ITSPmagazine | Technology. Cybersecurity. Society
From Threat Intelligence to Cyber Resilience: What SMBs and Enterprises Need to Know Now | A Brand Spotlight at RSAC Conference 2026 with Tony Anscombe, Chief Security Evangelist of ESET

ITSPmagazine | Technology. Cybersecurity. Society

Play Episode Listen Later Apr 1, 2026 24:01


On the RSAC Conference show floor, Tony Anscombe shared how ESET has expanded its threat intelligence offering with ECR reports -- designed to give commercial organizations both machine-readable feeds and human-readable analysis. The reason: threat actors are increasingly hard to attribute, they share tools, run coordinated campaigns, and reinvest profits into more sophisticated operations. Having someone do the research and surface actionable intelligence is no longer a luxury. Anscombe pointed to a telling campaign pattern from last year: threat actors refined attack methods against UK retailers, then rapidly adapted those same techniques against US retailers. The implication is clear -- your business may be unique in its infrastructure, but it is not unique in its sector. Understanding how your sector is being targeted is the foundation of a prevention-first posture. Automation came up as equally non-negotiable. If it takes three days to collect all the information needed to make a determination about an incident, the post-attack phase has already begun. ESET Inspect is designed to flip that equation: when an analyst opens an incident, the forensic analysis is done, the evidence is visualized, and the determination can be made on facts rather than gathered through investigation. Anscombe was careful to draw a line between automation as speed and automation as replacement. ESET's position is that AI should operate alongside human expertise -- trust and verify applies to AI-assisted analysis just as it does to any intelligence feed. Oversight remains essential, even as the tooling gets faster. A preview of upcoming survey data offered one of the more striking moments in the conversation. Roughly 35% of SMBs using MDR are sourcing that service directly from their cyber insurer. Anscombe flagged the monoculture risk: when a large share of businesses in the same sector run identical security stacks, a single point of failure becomes a sector-wide vulnerability. His advice after 30 years in the industry -- different organizations should deliberately choose different platforms to maintain diversity. This is a Brand Spotlight. A Brand Spotlight is a ~15 minute conversation designed to explore the guest, their company, and what makes their approach unique. Learn more: https://www.studioc60.com/creation#spotlight GUEST Tony Anscombe, Chief Security Evangelist, ESET LinkedIn: https://www.linkedin.com/in/tonyanscombe/ RESOURCES ESET: https://www.eset.com ESET Threat Intelligence: https://www.eset.com/int/business/services/threat-intelligence/ Are you interested in telling your story? ▶︎ Full Length Brand Story: https://www.studioc60.com/content-creation#full ▶︎ Brand Spotlight Story: https://www.studioc60.com/content-creation#spotlight ▶︎ Brand Highlight Story: https://www.studioc60.com/content-creation#highlight KEYWORDS Tony Anscombe, ESET, Sean Martin, Marco Ciappelli, brand spotlight, brand marketing, marketing podcast, threat intelligence, cyber resilience, MDR, EDR, XDR, managed detection and response, SMB security, cybersecurity automation, RSAC Conference 2026, prevention-first security, cyber insurance, monoculture risk, ESET Inspect, APT research Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.

The CyberWire
Your phone works for them now.

The CyberWire

Play Episode Listen Later Feb 9, 2026 26:24


Ivanti zero-days trigger emergency warnings around the globe. Singapore blames a China-linked spy crew for hitting all four major telcos. DHS opens a privacy probe into ICE surveillance. Researchers flag a zero-click RCE lurking in LLM workflows. Ransomware knocks local government payment systems offline in Florida and Texas. Chrome extensions get nosy with your URLs. BeyondTrust scrambles to patch a critical RCE. A Polish data breach suspect is caught eight years later. It's the Monday Business Breakdown. Ben Yelin gives us the 101 on subpoenas. And federal prosecutors say two Connecticut men bet big on fraud, and lost. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Our guest is Ben Yelin, Program Director for Public Policy & External Affairs at the University of Maryland Center for Cyber Health and Hazard Strategies, talking about weaponized administrative subpoenas. Selected Reading EU, Dutch government announce hacks following Ivanti zero-days (The Record) Singapore says China-linked hackers targeted telecom providers in major spying campaign (The Record) Inspector General Investigating Whether ICE's Surveillance Tech Breaks the Law (404 Media) Critical 0-Click RCE Vulnerability in Claude Desktop Extensions Exposes 10,000+ Users to Remote Attacks (Cyber Security News)  Payment tech provider for Texas, Florida governments working with FBI to resolve ransomware attack (The Record) Chrome extensions can use unfixable time-channel to leak tab URLs (CyberInsider) BeyondTrust warns of critical RCE flaw in remote support software (Bleeping Computer) Hacker Poland's largest data leaks arrested (TVP World) LevelBlue will acquire MDR provider Alert Logic from Fortra. (N2K Pro Business Briefing) Men charged in FanDuel scheme fueled by thousands of stolen identities (Bleeping Computer) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc. Learn more about your ad choices. Visit megaphone.fm/adchoices