The Segment

Illumio

Attackers are smarter, more sophisticated and move more quickly than ever. If your organization hasn’t been breached yet, odds are you will be. On The Segment, you will hear from industry experts about the latest cybersecurity trends. We will unpack how modern organizations can reduce risk and curtail impact with Zero Trust - a “never trust, always verify” approach to cybersecurity. Join us for The Segment: A Zero Trust Leadership Podcast, brought to you by Illumio.

  1. 8月5日

    Hackers Don't Break In. They Log In. | Keren Elazari

    Hackers don't break in — they log in. That's the refrain cybersecurity researcher, TED speaker, and self-described friendly hacker Keren Elazari keeps coming back to, and it sets the tone for a conversation that cuts through a lot of the current AI hype. Host Raghu Nandakumara sits down with Keren to talk about why, despite the constant headlines about AI-discovered zero-days and autonomous attack tools, the overwhelming majority of real-world breaches still come down to the same fundamentals: stolen credentials, unpatched known vulnerabilities, and social engineering. Keren points to Verizon's DBIR data showing that over 80% of web-facing attacks are credential-based, and to the CISA KEV catalog, where under 30% of known exploited vulnerabilities are even patched — numbers that make the "AI supercharges vulnerability discovery" conversation feel a little beside the point. The two dig into what Keren calls the widening asymmetry between attackers and defenders: AI is getting good at finding vulnerabilities and writing exploits, but not nearly as good at patching them or getting fixes into messy, real-world production environments. She describes AI as "a time machine for attackers" — compressing weeks of reconnaissance and tooling into hours — and argues defenders need that same acceleration applied to mitigation and containment, not just detection. The conversation also covers: Shiny Hunters' evolving social engineering playbook — from impersonating employees to get help desks to reset access, to now impersonating the help desk itself to harvest credentials via fake SSO resets, SIM swapping, and deepfake voice tools The GTG-1002 incident referenced in Anthropic's late-2025 report, where a nation-state actor used an AI model as an active accomplice in an orchestrated attack, and why Keren thinks the sophistication was in AI-driven orchestration, not novel exploit creation Shadow AI as a new attack surface, using the rapid, often misconfigured spread of local "Open Claw" installations (many left listening on all ports) as a cautionary example Jade Puffer, an early example of agentic, largely human-out-of-the-loop ransomware, and why Keren wasn't surprised given how much ransomware groups already reinvest in R&D A malicious-package incident on Hugging Face, and the broader pattern of attackers targeting trusted open-source "watering holes" like GitHub and model/skill hubs Keren closes out by introducing her reframed security fundamentals — Identity, Visibility, and Containment (IVC) in place of the classic CIA triad — and makes the case for "proactive paranoia": preparing for breaches before they happen rather than scrambling once they do. She and Raghu wrap with a shared hard truth: for all the AI conversation, security is ultimately about serving the humans on both sides of the equation, including the fact that attackers are humans too, and often know an organization's environment better than its own defenders do. Stay connected with our host Raghu on LinkedIn For more information about Illumio, check out our website at illumio.com

    Hackers Don't Break In. They Log In. | Keren Elazari
  2. 7月15日

    AI Doesn't Break Security. It Exposes It. | Jason Garbis

    Most security breakthroughs don't come from new technology, they come from finally getting the basics right. As AI accelerates both attacks and the pace of vulnerability disclosure, the organizations that fare best aren't the ones chasing the next big thing, but the ones with the visibility, governance, and segmentation to absorb the shock. In this episode, Raghu Nandakumara sits down with Jason Garbis, founder and CEO of Number Line Security and co-chair of the Zero Trust Working Group at the Cloud Security Alliance, to explore what Zero Trust looks like when threats evolve at machine speed. Jason draws on his path from early software-defined perimeter work to leading Zero Trust strategy at the Cloud Security Alliance, sharing why "right-sizing" a Zero Trust initiative matters more than chasing sweeping transformation, and why even a well-built security capability fails without genuine buy-in from the business.  The conversation then turns to AI's effect on the threat landscape: the surge of vulnerabilities and patches enterprises now have to absorb, the widening gap between attacker speed and defender response, and why segmentation remains one of the most effective ways to shrink the blast radius of an attack. Raghu and Jason discuss: How to right-size a Zero Trust initiative for an organization's actual readiness Why "build it and they will come" doesn't work for security adoption Tying Zero Trust investments to business priorities like AI adoption, M&A, and compliance What's genuinely new — and what isn't — about securing AI systems and agents How accelerating vulnerability disclosures are reshaping patch management Why segmentation reduces blast radius even when patching can't keep pace A simple analogy for explaining zero trust to non-security stakeholders Jason closes with his go-to way of explaining Zero Trust to non-technical stakeholders: an analogy involving brakes, oil, and seat belts that reframes security as a shared responsibility rather than a roadblock. Resources Mentioned: Zero Trust Security and Enterprise Guide   Stay connected with our host Raghu on LinkedIn For more information about Illumio, check out our website at illumio.com

    AI Doesn't Break Security. It Exposes It. | Jason Garbis

關於

Attackers are smarter, more sophisticated and move more quickly than ever. If your organization hasn’t been breached yet, odds are you will be. On The Segment, you will hear from industry experts about the latest cybersecurity trends. We will unpack how modern organizations can reduce risk and curtail impact with Zero Trust - a “never trust, always verify” approach to cybersecurity. Join us for The Segment: A Zero Trust Leadership Podcast, brought to you by Illumio.

你可能也會喜歡