Cybersecurity Perspectives

S1:E4 - 42% increase in zero-day vulnerabilities & Phishing leading AI Assisted Initial Access

• Paul Marco & Owahn Bazydlo • Season 1 • Episode 4

Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.

0:00 | 43:58

Security is moving faster than the people trying to stop it - and attackers are already using AI to widen the gap. Tom Hafemann joins Owahn Bazydlo and Paul Marco for a sharp, unfiltered conversation about why vulnerability exploitation, patching, third-party risk, and AI-powered attacks are becoming harder to ignore.

The episode starts with a sobering stat from the 2026 CrowdStrike Global Threat Report: a 42% increase in zero-day vulnerabilities exploited before public disclosure. But the real value here is how the conversation turns that number into practical reality. Tom, who has spent 30 years building systems on the community finance side, brings a defender’s eye to the chaos, while Owahn and Paul break down what it actually means to operate securely when every new control seems to create three more problems.

You'll discover why access segmentation and separate admin accounts matter more than most teams want to admit, why third- and fourth-party risk is now a business-critical blind spot, and why cyber insurance carriers are so focused on vendor exposure. The group also gets into the limits of patching, the tradeoffs between security and functionality, and how organizations can prioritize vulnerabilities based on what is truly in their environment, not just what looks scary on a report.

Paul introduces what is leading AI-assisted initial access stats from the 2026 Verizon Data Breach Report, including phishing leading with 44% of initial access and vulnerability exploitation at 32%, and the conversation quickly widens into the reality of adversarial AI. The panel explores how attackers are using generative tools to produce better phishing, faster malware, and more convincing impersonation, while defenders are still figuring out how to govern AI safely inside the business.

Tom, Owahn, and Paul also dig into the deeper shift underneath all of it: the move from trusting passwords, to voice, to video, and now back to safe words and human verification. It is a practical reminder that cybersecurity is cyclical, and that the tools changing the game for defenders are usually the same tools empowering attackers.

Essential listening if you care about vulnerability management, cyber insurance, third-party exposure, or the future of AI in security. If you are responsible for protecting people, systems, or data, this conversation gives you both the urgency and the perspective to think more clearly about what comes next.

https://www.talas.io/podcast

People on this episode