Cybersecurity Perspectives
Cybersecurity Perspectives is a show for IT and cybersecurity professionals who want real talk, not talking points.
Every episode, a guest draws one of three cards, each one holding a real statistic pulled from an industry report or news outlet. Whatever card they pick becomes the topic. No pre-set questions, no rehearsed answers. Just an honest conversation about what that number actually means for their company, their team, and the industry at large, and what to do about it.
Hosted by Paul Marco and Owahn Bazydlo, co-founders of TALAS Security, the show brings together practitioners, leaders, and builders from across IT and cybersecurity to talk shop, share hard-won lessons, and build a stronger community for the people doing this work every day.
Stats. Insights. Real talk.
https://www.talas.io/podcast
Cybersecurity Perspectives
S1:E4 - 42% increase in zero-day vulnerabilities & Phishing leading AI Assisted Initial Access
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
Security is moving faster than the people trying to stop it - and attackers are already using AI to widen the gap. Tom Hafemann joins Owahn Bazydlo and Paul Marco for a sharp, unfiltered conversation about why vulnerability exploitation, patching, third-party risk, and AI-powered attacks are becoming harder to ignore.
The episode starts with a sobering stat from the 2026 CrowdStrike Global Threat Report: a 42% increase in zero-day vulnerabilities exploited before public disclosure. But the real value here is how the conversation turns that number into practical reality. Tom, who has spent 30 years building systems on the community finance side, brings a defender’s eye to the chaos, while Owahn and Paul break down what it actually means to operate securely when every new control seems to create three more problems.
You'll discover why access segmentation and separate admin accounts matter more than most teams want to admit, why third- and fourth-party risk is now a business-critical blind spot, and why cyber insurance carriers are so focused on vendor exposure. The group also gets into the limits of patching, the tradeoffs between security and functionality, and how organizations can prioritize vulnerabilities based on what is truly in their environment, not just what looks scary on a report.
Paul introduces what is leading AI-assisted initial access stats from the 2026 Verizon Data Breach Report, including phishing leading with 44% of initial access and vulnerability exploitation at 32%, and the conversation quickly widens into the reality of adversarial AI. The panel explores how attackers are using generative tools to produce better phishing, faster malware, and more convincing impersonation, while defenders are still figuring out how to govern AI safely inside the business.
Tom, Owahn, and Paul also dig into the deeper shift underneath all of it: the move from trusting passwords, to voice, to video, and now back to safe words and human verification. It is a practical reminder that cybersecurity is cyclical, and that the tools changing the game for defenders are usually the same tools empowering attackers.
Essential listening if you care about vulnerability management, cyber insurance, third-party exposure, or the future of AI in security. If you are responsible for protecting people, systems, or data, this conversation gives you both the urgency and the perspective to think more clearly about what comes next.
https://www.talas.io/podcast
Cybersecurity moves fast. Working on a space measured in minutes and seconds means we can't expect to keep pace by doing the same thing over and over. The sharing of perspective across technologists, defenders, business, and professionals is key to unleashing internal capability. Perspective comes from sharing experiences and ideas.
Speaker 1Welcome to Cybersecurity Perspectives. Hello, everyone, and welcome back. Here we are on episode four, is it, Owen?
SpeakerI think so. But really, this is the first one, right? Because we have Tom here.
Speaker 1Well, that's the that's the guest. That's the benefit, right? Here, that's the gift. We actually have a guest. We can we trick someone into being on our podcast finally.
SpeakerExactly.
Speaker 1So, ladies and gentlemen, I'm actually super excited for this guest. This gentleman is hailing all the way from his content, and he has been in technology for most of my life. 30 years. He's been building systems, making systems work, and he has been doing this on the community side of finance. It is my pleasure to welcome Tom Hafen. Tom, welcome to the show.
Speaker 2Yeah, it's a pleasure to be here and finally get to talk with you guys.
Speaker 1I know, I know. It's been a lot of buildup, and now we get to actually get into it. And we've been talking about this whole format for so long, and now we actually get to do the thing.
Speaker 2Yeah, I'm really excited, kind of nervous about having to pick one of three. It's kind of like the uh the game show. It's door one, door two, door three.
SpeakerExactly, right? Yeah, I think that was from Let's Make a Deal, if I'm not mistaken. Let's make a deal, right? Yeah, there we go. See, I got a little throwback history, Emmy.
Speaker 1Well, I'll tell you, that's actually what I love, right? This is like one of the reasons why we did this and why we chose to do it is because I also enjoy this. I have no idea what we're gonna pick, right? It could be a complete dud. But you know what it is? Like that shared vulnerability is gonna be the key for us.
Speaker 2Yeah, well, you know, we experience that almost every day, right? When something happens, you just don't you plan out your day, and all of a sudden something comes in, you're like, hmm, let's deal with it.
SpeakerIt's so funny that you bring that up, Tom. Is one of the things that I've kind of embraced um is this notion of you have to be comfortable being uncomfortable in this space, right? It's such a weird concept to understand, but it's something that ironically, maybe I was birthed with or not. But um, the other topic that I think sometimes is a glutton for punishment, right?
Speaker 2I don't think we actually seek it out. It just kind of happens along the way, though, right? Yeah, agreed.
Speaker 1Awesome. Well, before we get into the cards, right? Before we experience this shared vulnerability, anything uh interesting happened this week, gentlemen? Any any fun stuff for report from uh the news, your your world, or anything like that?
Speaker 2Um, there's always something coming out in technology, and uh it's been kind of quiet. Uh, I think the the biggest thing is Dolly Parton right now. It's like what's happening with Dolly Parton?
SpeakerUm agreed. And and agreed, I think, person as well as just a contributor to I think society overall. Um, I think one of the ones that I kind of came across, because Tom, honestly, Paul caught me off guard on one of the other episodes uh on the same question. Um I was just coming back off vacation. Uh, so my response was uh no, I don't really have anything. But uh this week I actually did have something, I think it's a recurring problem. The one article I was reading was a lot about admin credentials within specifically the entre environment. But I think this notion of admin credentials and the lack of value that this actually holds in companies, I think is really interesting. And it brings me back to the perspective of it's one of the hardest things I think to really operationalize from what do you need administrative accesses for rather than what do you just need to do your daily job, right? So for example, I don't need admin rights to just do email back and forth with whoever, right? Internal, external, but I do need admin rights to go do configuration in a certain application. Yet I'm seeing this as a big operational issue as it comes to how do I get my administrators to actually have another normal account in which they're switching back and forth, right? Um, so it was just a topic, an article that I read. Um, there's some exploits on it. I think we all know about that. Um, but it's something that's really hard to solve.
Speaker 2Yeah, I know, you know, big things around us are have to do with that. You know, back in the day it was you were either an administrator or you were a user, and you maybe had a few other roles in Madonna. Now intra ID comes in and you got 60 different types of security roles, and you can no longer, you know, Duo and Microsoft announced that they're no longer going to be doing voice or SMS two-factor authentication anymore. Uh that's February uh 27. So everybody else is jumping on board. No more texting because texting is uh number one thing in fraud in my industry. Uh text going back and forth. But you but you're right. Uh uh who's gonna have the break glass key uh uh keys, where do they exist? We're looking at YubiKey as a as a as a yeah, I'm thinking that's gonna be more of that, but having to divide those uh credentials uh of what would you what you're talking about is basically zero trust, zero trust networking, and just uh give you enough to do your job, but uh not enough to get you in trouble, especially if you are compromised.
Speaker 1Let me tell you guys, I love this. So access segmentation is my jam. I'm probably like one of like the six people on the planet that love IAF, right? It's weird. I don't know why, but I love it. Okay. And uh every time we go into a client, like one of the first things I look for are are the network admins using their mobile accounts for doing that, right? And every now and again I'll come across it and I'll tell them, like, hey, listen, we gotta set up a setup account for you. You have to make sure that you have that segmentation, and I like the death stage like that, the daggers that get shot my way. I've had people ask that, how am I supposed to do my job? But they always see the way, right? I always are like, oh, this makes a lot of sense. I feel more secure, that type of thing.
Speaker 2And I think it's a it's a journey, as in anything, right? Yeah, because most people are like, I can do my job perfectly with an admin. It only takes one something to happen before they go, oh, maybe that's not a good idea. We're looking at actually having multiple admin accounts, not just a single admin and user account. And and and basically, if you're gonna do this function, this is that account. If you're gonna do this function, that's account. And um, yeah, just you're right. You're you're right at your spot on there with uh segmenting not only the accounts, but multiple accounts for the same person.
Speaker 1Yeah, absolutely. I I always advocate for at least three. One for your servers, no domains, no endpoints, one for the endpoints, no servers, no domains, and then one for the domain, of course, the other two are omitted. Now, we could get crazy. I'm gonna really start getting into segmentation, but then we get into that balance of, hey, Paul, take your tinfoil hat off. You're getting a little crazy with it, right?
Speaker 2Yeah, there's there there's always been, you guys know it's always been a balance between security and functionality. I mean, if you if you want ultimate security, you unplug and go back to paper and pencil, right?
Speaker 1Yeah, it's true. The most safe server is unplugged and buried under four feet of concrete, right? Yep.
SpeakerAs we all know, the business is gonna fire immediately if that's your only solution.
Speaker 1Amazing. You know, this is why I already love this podcast. We could talk about my favorite topic going like five minutes in. This is amazing. Yeah, right. This is gonna be a good one. Well, I think it's that topic, guys. Are we ready to start picking some cards? Think so.
Speaker 2Yeah, oh man, door number one, door number two, door number three. I'm gonna go right in the middle, door number two. All right, so listen.
SpeakerThe inaugural first card flip. Let's go.
Speaker 1The first card flip was uh was a B. So listen, for those of you listening, you know, this is the first couple of episodes. We have three cards on the table. Tom has selected B, and whatever is on that card from a statistic perspective, that's what we're gonna talk about. Now, we've sourced these statistics from a couple of different industry reports and news articles, and here we go. This is our topic for today. Okay, so the the category for this film is vulnerability exploitation and patching. And this actually comes from the 2026 CrowdStrike Global Forgot Report. And according to them, the statistic we're gonna cover today is that 42%, there's been a 42% increase in zero-day vulnerabilities exploited prior to public uh disclosure. So we're almost 50% in terms of vulnerability exploitation, zero-day vulnerability exploitation prior to those vulnerabilities being uh being disclosed.
Speaker 2Ouch. Yeah, that's uh that's that's an interesting statistic. Um, I found it interesting it came from CrowdStrike. Um, we could probably talk about CrowdStrike until we're blue in the face about basic what happened a little bit ago. Um, but if anybody's gonna learn about problems, it's gonna be somebody that's gone through them, right? Um you know, my my security person and I, we were talking about uh one statistic that we heard like 60 160 vulnerabilities are released every day. And we're like, that's it. And we said, there are just so many vulnerabilities that are out there, they're just not acknowledged until they're acknowledged by somebody who says, we got a fix for this vulnerability. And to see that keep rising and rising and rising, you gotta kind of wonder do there was a time in my career where functionality was more important than security. In fact, we get driven by, hey, we need to get this out, we need to get it working. We we we need to be the first one to the market on this, we need to get this working. And it sounds like we're coming back to it again. Let's get this working and then try to bolt on security later on, or don't go through the proper channels to uh to get it on. I'm actually kind of surprised that AI isn't more involved with that conversation about if I build something, can I test it for vulnerabilities before I get it out? What are you guys thinking?
Speaker 1So there's a bunch, and I think I knew AI was going to become a part of this topic, and it only took about 36 or 37 seconds, so that's good, right? As technologists, there's no way we can't help ourselves, right? Um, but I think that's actually why this number is so high in 2026, is because we have things like the mythos model, right? So anthropic release mythos and mythos is purpose built for finding vulnerabilities. And the number of like zero-day vulnerabilities that zero disclosed has been higher than any year prior. And that's why this number is so high. That's why there's 42% more disclosure than there was that in the year prior. So, like, I think year spot on though, right? Because here's the problem the problem is we're talking about attackers looking for vulnerabilities and the and and utilizing zero-day vulnerabilities prior to disclosure. Well, that's all part of the renting side, that's all part of the attack side of the command draw. Time where your head is at, is on the defender side, and that makes a ton of sense, right? So, how do we use those same models to basically be preemptive, right? And get ahead of these things and start to hit our own stuff with these same models to find those vulnerabilities in zero days, not only to disclose them responsibly, which is the right way to do it, but then to just make sure that our stuff is patched and protected so it can't be exploited.
Speaker 2It was one of those things where we always uh I was an early open source adopter, you know, just like really, really, really early in open source. And one of the benefits we always talked about open source is you have this team of volunteers that is looking at systems, making them better, making them more secure. And kind of I'm at at one point we bought into it, but now I'm wondering is there enough of the the black hats or the the gray hats that are out there that are trying to exploit it? I think you know SSH was one of those really, really high level exploits a number of years ago. You're like bad people pretending to be good people, pretending to be bad people, and just like where where do you go with this?
Speaker 3Well, getting upstream where? Yeah, yeah. How do you inject that?
Speaker 2I'm I am a bit surprised that number is as high as it is, but at a certain point, if you've been in technology long enough, you can ex you've you've been exposed to things. Hey, this is this is a problem, and you tell the developer about it, and they're like, Well, you're the only one that's ever reported this problem, therefore it must not be a problem until a fix comes out six weeks later, six months later, and you're like, I told you about this, this is a problem.
Speaker 3Right.
SpeakerWell, I I think that's a bigger part too, is when we look at the business element of that, right? And I think you're bringing it up, Khan, is a notion of, okay, there is a vulnerability, something's been exploited, right? If we look at other industries, um, even from the the credit validation uh entities that we have seen being compromised, what actually impacts their business at the end of the day? I what are we issuing? Maybe a month worth of uh privacy or you know, a month worth of monitoring for your personal accounts. So my bigger thing is we have to articulate why this is more important for the end users as well as internally. Um, I thought you brought up a great point, right? We could have way more vulnerabilities. This stat only talked about obviously disclosing ones, but at the end of the day, every vulnerability is not equal, right? So your company may not be facing a tenth of the percentage of the global vulnerabilities that occur. But it's, I think our job, at least where my head goes within vulnerability management, is that privacy is really important to me. And it's how do we actually inform our operations or our company of vulnerabilities or exposures that we have, and then how do we deal with those, right? For me, a lot of the times it's I want clients or customers to feel comfortable in our methods and our process to respond to rather than saying that there will never be uh an opportunity, right? And that's basically what vulnerabilities are. Whether you patch them quick enough or whether you're exploited through them, that's theoretically that vector of that sprawl which would impact the client at the end of the day.
Speaker 1Yeah. I think you're spot on. I think you're spot on.
Speaker 2You brought up you brought up patching, and I know that patching has been uh a pain point, um, at least in my entire career, is when do you patch? How do you patch? Do you patch right away and live with the consequences of breaking something that the patch kind of closed up? Like uh uh what is that uh print nightmare that ended up coming out? You guys remember print nightmare? I did. Uh uh it was appropriately named, and all of a sudden printing didn't happen, but you were gonna plug a hole on print nightmare, and you're like, oh, we're gonna be secure enough so that we can't print anything ever again. Um and it's just out of reality, right? I you you gotta you gotta live with this stuff. And I think many businesses have got to take the risk model and actually understand what risks they're gonna be taking. Being in finance, we got to say we're in the risk business, whether it is um lending out money or are we gonna get it back? There's just some some inherent risk about being in business. And to articulate what your risk proposition is or what you're comfortable with, um you also mentioned that not all every risk is a risk that applies to us. For example, I think some CVEs just came out for VMware, and um we looked at what they were, and this is part of the the nightmare of patching or security. You gotta read it to say, okay, how probable is this? And and what are the chances of it actually happening? And if it does happen, what what do they get?
SpeakerRight? I love how you brought that up. From there was one person back in corporate that was really good on the vulnerability team that was extremely intelligent and knew a lot of the software underlying processes and understanding the systems of how to external exposure versus just internal operations. And most of the times he came back constantly for you know, nine CV rating on your vulnerability. And then he'd be like, there's no way that this can be exploited in our environment, right? You would literally have to be in this one particular rack closet to plug in to actually have that exposure. And like, though that's the context that I think helps to quell this massive sea of vulnerabilities, right? Um, but not a lot of people understand how to navigate through that. But having resources that understand end-to-end processes and and where things can be actually taken advantage of is huge.
Speaker 1Yeah, and I think that bringing it back to the statistic here, right? Like, this is my big concern is that this these statistics are terrifying. And part of that is because our industry is really good at selling fear. I hate that. Oh, I I hate that it's like, well, hold on, like all these zero days are out and it's for up 50%, which means you have to buy my tarnocks or whatever that's right. And like that's true, but it's also not true. What you guys were just talking about is understanding the network, right? You talk about the vulnerability for VMware and how to approach it and where does it live on the network? How many companies don't use it? It's not a problem, right? That that zero day could be out and the metric could be out. But if no one is using that particular thing, who cares? Right? Like I used to use the example between exchange and lotus notes. If a lotus notes vulnerability comes out, I'm gonna be like, okay, cool, let's get some lunch, right?
unknownRight?
Speaker 1Like, all right, it doesn't matter. So like this is where I think that folks like us, right? Like folks that are listening to this podcast, the people that are in charge of making sure that the organizations are safe, part of doing it is really understanding like what is the composition of your network? What do you have? Like, how does it, how is it laid out? How are people using it? How's your data flowing? And that in and of itself sounds a little overwhelming. But as you start to break things down into what are the technologies that are out there, like what are the data sets that are out there, who are the people that are accountable, right? And breaking it down into this framework, that's where we can start to look at these things and say, yeah, ah, there's my clarity. We can make sense of this and prioritize the vulnerabilities that do come out.
Speaker 2And you know, I'm gonna take this a little step further because this is an interesting conversation because we're we're having this right now. I think we got our systems locked down pretty good. I mean, we we we get the criticals, the highs, the mediums, and all that stuff, and we can deal with that stuff internally. We can have a conversation about that. With the advent of third parties and fourth parties, those are where I think we get in the most trouble because we don't know what's happening with the third parties and the fourth parties. They could have a SOC, they could have a plan in place. Is it really happening? We got no insight into their systems of exactly what's happening. So when you hear about some of these vulnerabilities or what's happening, there's no way you can reach out to all of your third party who also has third-party vendors, um, to make sure that they can give you answers to that as well, right?
SpeakerLike most of the times they're not even gonna provide you an answer.
Speaker 2Yeah. Um, so so part of it is basically you almost have to close your eyes and say, Lord, I hope you're doing the right thing. You know, uh, and but you honestly don't know. Um, and that's where I think it's kind of scary sometimes when some of these major things come out. Um, I think of the the the what is it, uh LastPass a few a few years ago. Like, oh my gosh, um, we are kind of all many people that were using it that were friends of mine that were using it were like, oh my gosh, all these passwords got compromised. And then you find out what their security was in the background. And had you known that, you would have never um gone with them. So um the whole patching, the whole vulnerability thing. You know what they say sometimes about statistics? Um, 70, 80, no, 92% of all statistics are made up on the spot.
Speaker 1I love it. I I I I went to school for political science and philosophy, and my poly sci uh scientist, which of course total scientists, all statistics, he used to say, be careful with statistics, because if you got one foot in a fire and one foot on a block of ice, on average, you're comfortable. Right? So I listen, I I gotta admit, I was a little worried when we started this thing. I'm like, are we gonna get to like our 30-minute mark and fill content? And then Tom over here brings up third parties, and now this episode is gonna go an hour and a half because I have a lot of opinions on third parties. I love that you brought it there, right? Because we always think about this from the first person, right? From the first person perspective, what are my concerns? What are my issues? But it's it's interesting, like I truly firmly believe that third party is becoming a much, much larger issue. And if we're gonna talk about things like patching and all the other controls we have to rely on these third parties for, like this is an issue. I remember I was shopping cyber insurance for with one of my clients. We met with a broker, filling out their questionnaire. Here's the controls. Here's how everything is laid out. And the broker was hyper focused on third party. How are you doing third party risk? How are you managing things? Are you looking at the SOT to the porch? Are you getting ISO certificates? Uh, you know, are you using the proper, you know, six set of questionnaires or all these things? So suddenly it was like, hey, listen, like we glossed over access, we glossed over these other things, but we spent a ton of time on third party. Why is that? And he looked in the he said immediately, he was like, listen, 50% of our claims that got paid out were because of third-party breach. We are hyper focused on two and point your area. And that's the problem, right?
Speaker 2Like third and third and fourth party, because even your third parties don't necessarily agreed. Um uh monitor their fourth parties uh well, especially if they're a mediator of that, like somebody will sell software and they're they're counting on that software. I I I think the the fourth party thing is is is huge. And with this big push to the cloud, to the cloud, to the cloud. Um, um, you're like, why? Really?
Speaker 1No, it's interesting.
Speaker 2Something else's data center that you hope that's all it is.
Speaker 1Yeah, that's all it is. And we used to say that all the time. It's not a cloud, it's just someone else's data center, right? Someone else's platform. It's interesting. The fourth party stuff makes me scary, right? Like the thing is, I I get it. Like, you have to understand who your vendors are, but now we have to understand what our vendors' vendors are.
SpeakerWell, that and that's where I think for me, it's to your point, Tom, fourth, fifth, sixth. I remember back in corporate too, especially at a financial institution, literally there was an issue to go down to fourth and fifth. Um, they have the resources, they can do that. Most organizations, if you're talking S on B, they can do third party. But this is where for me, it's about what's the actual problem set that you have control over? And for me, it's pointing back into as we make these contractual agreements, and this sort of becomes internally to your organization. We have to define actually how are you connecting, what's the data transfer, what are things that aren't safe, where's the encryption in the which you can control? And a lot of times that's the hard part, though, is the business is gonna say, I don't care about the controls in which you identified our high risks. We have to push that through. So within that exactly you're gonna go in tomorrow. And so within that, how do we build out at least defense in depth, right? So, okay, where this data resides, can we get more visibility, or the users of this particular data or system and tools can get more visibility, right? Because to your point, we can't keep chasing Vones. We can't keep chasing third, fourth, fifth, sixth, seventh, eighth parties. We really have to understand how do we interact with the data or the tools that are coming into our network or our systems. And that's where it's like, do we have control again? But this is really throwing everything from vulnerability as it's been taught over the last 20, 30, 4 years, to really put it on its head, right? You guys have more control rather than just looking to mitigate what's being pushed through there, right? So almost not a defensive perspective, but almost a toll gate of saying you're not getting through here perspective. Again, just something that I'm trying to noodle with over time.
Speaker 2Well, you you know, you guys are in security. I'm gonna say something that may be controversial, but it I think most of my time is managing the perception of security rather than the actual security that actually takes place. Yes, 100%. And if we can manage to the perception of security, uh sometimes I ask, do you actually want security, or would you like it to feel or see or look like it's secure? Because uh one costs a lot of money, the other one costs a lot of PR. So which one would you like? So um, and it that's the same way with what we're talking of third parties, fourth parties, uh the patching schedule, the the vulnerabilities that are released. If we really want to go down and feel secure, how much time is going to be spent reading all these CVs, finding out what's going on? And it only takes one to go, oh, I didn't read that one. Next thing you know, you're in trouble.
SpeakerRight. And I think it does occur to that we can talk about. And I think this might be, you know, again, Tom, you can like conclude this while I'll start off and I think Alice's. I think it's also easy as we make the third and fourth party micro-subspecifically is to you do transfer of risks, right? Making our concepts a little bit more tighter or better as it pertains to third-party interactions, and we just can highlight these opportunities of bonds specifically, um, that would work less. But it's just again there's a couple of opportunities, creativity and attention within the bone space overall, to take more control from an organizational perspective rather than something hey, the industry says you have to manage a billion bones. Like, come on, that's that's just not uh attainable, right?
Speaker 2Yeah, you guys get a microphone in here or something because you guys listening to us. Well, a number a number of years ago, and I talk about it all the time now. What sort of indemnification is our third and fourth parties providing to us to take on some of that risk? In other words, we're gonna believe in you, but ultimately, if something happens, you have to indemnify us against that risk and take on some of that responsibility for yourself. Where is that in the contract? Good point. Love that, love, love that conversation.
SpeakerAnything else? Do we have enough time for one more card? Or is this I don't know where we're in time, I'm just so enthralled with the conversation.
Speaker 2I know another we we can do another card. That's what we want to take time, ABS. Okay, well, so that was an interesting card, and uh, but I think I'm gonna go through your C or card C.
Speaker 1All right, well, I knew we weren't gonna get away from this, right? So this topic is AI-enabled threats and adversarial use. All right, this I mean this is gonna dominate what we've talked about we're talking about, right? And this is from the Verizon Breach Report. All right, so according to the 2026 Verizon Data Breach Report, uh, AI assisted initial access techniques, phishing led at 44%, followed by exploitation of vulnerabilities at 32% and credential abuse. So, again, what we're talking about here in the statistic, and I'll read it again, is we're talking about how attackers are using AI to increase their ability to gain access to organizations from a phishing perspective and then from an exploitation perspective in vulnerabilities. So we just killed the vulnerability conversation. So I think we're good on that front. The reality is like AI is gonna be it's gonna be everywhere in terms of its use relative to attackers, and then hopefully, if we can get our stuff together, defenders as well. So, one more time. In AI uh assisted initial access techniques, fishing led at 44%, followed by exploitation of vulnerabilities at 32%.
SpeakerSo I'm a little slow on this, but um, can I have a first question? So Paul, this is basically saying is that AI is being five better at fishing 44% in more success rates. Correct. Exactly. Once they have success rates after that, are we using AI to be 32% better at whatever they're trying to exploit in once we're that's right.
Speaker 2Well, I got some thoughts on that. Um, the first thought is a very, very high-level thought. It's something that I shared with uh my staff, students when I was teaching. Anything in life, as good as it can be good, is as bad as it can be bad. So if we look at AI and we say all these good, really great things that can happen with AI and the possibility of solving major complex problems, the bad it goes as equally to the bad side.
Speaker 3Sure.
Speaker 2Isn't that isn't that basically what we've been going back and forth with technology for the last I don't know how long? Um, somebody gets something good and then somebody uses it for bad purposes. I think the thing we can talk about is how Claude got out in the hands of bad people, right? Uh most recently, that's it was exposed and they got some of that code. Um that was just a matter of time, and people will use Claude. Um there's one of my favorite series. I don't know if I can talk about it, because it kind of it kind of goes to this. Um person of interest. If you guys have not seen person of interest, it's one of those um, I'm not gonna spoil it for everybody, but it's an AI type of scenario. Um but it it asks it answers these questions. If you can use AI to tighten things up, why can't you use AI to find the vulnerabilities? That's right. Um remember when it was easy if people misspelled words or or used poor English and all that? Those days are gone.
Speaker 1Oh absolutely. That whole that whole training sequence in your cyber training is is as obsolete at this point.
Speaker 2Um we put DKIM SPF uh DMARC records in place to kind of help rein that in a little bit, but they've f figured a way around it is to get inside of somebody's email and actually send off emails on their behalf. So it's uh this is one of those things that I think we're gonna be chasing for a long, long time. As good as we can make AI and productive and the things that it can solve, it's gonna be used for bad.
SpeakerAnd that's like that's apart from me for statistic, right? So fishing at 44% increase, uh, that was basically success rate. For me, we had our security at our first full-time hire in literally his day one of us start, had an email that was spoofed from my particular meeting, which is very difficult, it was felt first and last. And it actually said, Hey, so glad you started. And then it started to work down towards getting financial information, right? So our employee literally responded within three minutes and said, Hey, Colonel, what would you like me to do? And I said, Okay, cool. Got up out of my seat, walked over to his seat, and the human interaction element to say, Hey, just let you know this is not me. I'm raspy of this, but they're becoming meaning the AI element, to your point, they're becoming extremely good. Not only are they able to into better verbiage that sounds like your native language, they're actually able to pick off and understand social media cues in which they can start to do pointed attacks. Like that's where I think phishing is becoming this reinforced vector of entrance in which organizations constantly think about protection. Um, but they're becoming really, really amazing at it. Yeah.
Speaker 1And this is actually one of the things that that I got super attracted to cybersecurity about was the chess match, right? And like that's the thing people forget. People forget that uh there are threat actors on the other side of these logs, right? We get so to looking at alerts or at logs or bits and bytes and zeros and ones and patterns, you forget that there are real people in real places that are attempting to exploit our people. And this is exactly the issue with AI. As soon as AI started to get really good, I got really, really worried, right? I was super excited for myself, all the things that was gonna enable us to do and all the cool things we're gonna able to do, and how much has accelerated our ability to execute and and and deliver our services. But I knew in the back of my head that someone was immediately gonna start exploiting these things, and then we saw the up control models come out, things like Worm GPT, where we'll absolutely build malware on the fly. In fact, I was just talking with a buddy the other day, and like we were looking at like some of the different metrics related to like malware being delivered to the different organizations. And the thing is, like, it used to be hard. You used to have to like code malware, go through testing, do all this stuff, and then we would reuse that, and that's where signatures came from. But that's not the case anymore. It's all different, it's all code, all the code has changed, and it works perfectly. Yeah, yeah.
Speaker 2You've seen you've seen it maybe in some of the dark web things, malware as a service, phishing as a service, where where those actually actually existed. Now, I've never claimed to be a good coder. In fact, I wouldn't even hire me to do coding. Except for now, I can put an idea or a concept or uh a thought about what I want to accomplish in in one of the AI models that are out there. And uh, there are so many different. I've I went through a class, a 30-day class, about all these AI models that do different things. Like I could be I could be like a a singer. I could be a composer for songs for with different AI stuff with just thoughts and stuff like that. But the the thing that was um really um about coding is you don't have to be good at it. They want they want to know, do you want this in Python? Do you want this in C? Do you want it in this? And within within seconds, literally, you got a code. Now, it's not perfect. Uh, as you guys know, you you got this and you go, well, this won't work. And of course, it's usually complimentary. Well, of course you're right. I've got a better idea. I found this, well, whatever. Um, one of the one of the AI models isn't quite nice. Um, I think you guys use it and it will call you out and basically say, Well, that's a dumb idea. Um uh it's kind of funny it does that. But um, this this uh like you said, AI, the chess match going back and forth um is a problem that we're gonna deal with. And it's like exponential. It's going quicker and quicker and quicker and quicker.
SpeakerAnd so that's that's what I was gonna bring up too, is like the attackers, right? They don't have the same rigor as usually business or organizations do, right? From an oversight, from a governance, from a regulatory perspective, right? As you said, there's a lot of these AI models in which they're trying to do via the phishing vector, they don't necessarily care if it fails. Their opportunity right now is spend more money, use AI, get quicker, and get faster. Whereas that's almost the inverse for a lot of auto or even small businesses to say they can't just immediately rip their requirement on this new capability of AI because of the straw, because of the privacy issues, because of the lack of control. So we're we're constantly inherently behind rate call, right? So this is allowing uh the speed of attackers to exemplify or exponentially grow. Well, we're all getting played out as we stick here out how can we produce our environment, how can people abuse it, how do we not be liable to actions from it? So that's where I'm just I'm not surprised, right? That this advertised is 44% irrelated. How do we think this is just more towards 120%, to be honest?
Speaker 2That they wouldn't surprise me at all. Um, I'll tell you one of the things that we've been talking about here uh among our executives, at what point do we say, I have to see you, I've got to touch you, uh you've got to be physically in my presence to prove who you are and say what you actually want. Um we're at the point right now when we get requests, um we gotta we have to go and verify with that person. Like, yeah, okay, is this you? Um because uh like I said, it used to be this was such a neat way, a quick way to to do business, and now people said, Oh, it's a it's a neat and quick way to get rich through scamming people as well. So we're almost going back to you gotta see me, you gotta do this in front of me. We can maybe use these th these models um to help us along, but to actually make decisions on things, but you know, we're gonna do another thing.
Speaker 1You triggered some for me, Tom. And it's exactly this thing. And I keep maintaining this theory that everything in cybersecurity is cyclical, right? And what you just described explains how this cycle works, right? Because back in the day, what did we need? We need a simple password, right? Put in your password and need to do something like a wire transfer. Sure. Now AI comes along, you start to see the face clone, we start to see the video changes, right? Audio, or right, or even even the show on this. So now the passcode wasn't good enough. So what did we say? Because people would start to hack the password, they'd say, hey, if you're gonna do a wire transfer, make sure to get on a video call with someone. Okay, well, then the AI, you know, face quality comes out. So then what do they said? They say, All right, well, listen, make sure you get on the phone and you you you talk to someone. And now we're we're cloning voices. So, what are organizations doing now? They're establishing safe words, right back to passwords. They went to voice, they went to video complications, but right back to passwords. That is the cybersecurity cycle that happens every time they think about some of this now.
Speaker 2Well, yeah, there there are so many cycle things like that in in in in technology. You know, I'm gonna I'm gonna decentralize compute, I'm gonna do PCs, and then I'm gonna do VMware, and I'm gonna go to centralized computing, and then I'm gonna go to the cloud, and then I'm gonna get these PCs, and I'm gonna use uh the processing that you're not using for internal processing, and then cloud, and it just keeps it. We're the rats on that wheel, you know that, right?
Speaker 1We just keep going. We're going nowhere. These conversations have been amazing. I love where the statistics took us. Listen, in these last couple minutes, if we end up recap, like what are the things we want to take away from this conversation? What are what is what's resonating with each other?
Speaker 2Um security is it is is everybody's business. Everybody's got to stay vigilant. Um, it's gonna get it's gonna continually uh most people have got to be on the alert for security. There's only so much an institution can do, organization can do to protect somebody. It's really got to go down to the to the actual person uh protecting themselves. Does this sound right? Does this look right? Does this smell right? And uh we can do as as much as we can, but ultimately people have got to be on their guard as well.
SpeakerNo, that's amazing. I mean, I think for me what you're talking about, Tom, is this notion of ownership at the end of the day, right? I think a lot of the traditional bid lines of businesses for everyone is about finance, right? Be a good corporate citizen or be a good business member to be financially responsible. I think cyber is a business enabler, but we have to articulate that about from the cyber perspective for the business. But the more that we get champions are understanding that every employee's responsibility, just as fiduciary expenses, we also have to be cyber aware and be really cognizant of that, right? Um, I ate the term a lot of the times that an Eric say a lot is see something, say something, but it really resonates with me now more than ever. If you feel something, don't be afraid to say something human to human, right? Um, to be able to kind of get those points across and to bring that awareness and back to the core of the operational rigor, right? The differentiator of businesses. But just something as far as me.
Speaker 1Yeah, I think the people defense is critical. And if I'm reflecting on the things we've talked about, there's a pretty clear theme for me, and it's velocity. Things are going faster. They're going a lot faster because the same tools we're using to make our services better, to deliver for our customers, whether it's a community financial organization, whether it's people that are being provided cybersecurity, those same exact tools are being used by the attackers to monetize and monetize at scale faster and more dangerous than ever.
SpeakerAnd that's what I always say too. I was saying I don't always like to use sports allergies. Okay, I kind of do, but um if the velocity is the issue, that means that you're really fast at speed, right? Well, then I'm gonna be bigger than you. And when you meet this brick at my business point, you're not gonna go any further, right? So if you're quicker, I'm gonna be bigger and stronger, right? If you're bigger and stronger, I'm gonna be quicker and smaller. So it's just trying to not meet your adversary where they are, it's trying to understand your adversary and then meet them where you have capability.
Speaker 2That chess game. Yeah, that's it. That's the chess match. That's it's the chess match and security. The good thing is, is because we're in security and we're technology, um, we're gonna have a job for a very, very long time talking about this stuff.
SpeakerThat's the best note, and uh, I love it, Tom.
Speaker 1That is true. That is true. A little bit in job security. Let's keep those vulnerable vulnerabilities rolling, boys. Right?
Speaker 2Attackers keep rolling. Thanks a lot, guys, for having me on the show.
Speaker 1Really appreciate it, Tom. Thank you.
SpeakerAny last-minute things that you wanted to kind of shout out for yourself, Tom? Or again, we couldn't be more thankful for your time.
Speaker 2No, I uh um just I'm just thankful to be here. Um technology guys, keep click keep learning, keep plugging away. Uh fight the good fight uh in your in your in your battles on a daily um daily uh work that you end up doing. And uh we're we're glad that you guys are out uh there with us.
SpeakerBut can be happier, Tom, that you're a participant in this community. You can't wait to stay with groups and look forward to you uh pursuing more. So thanks to watching. Thanks a lot. Thank you so much.