Discussion about this post

User's avatar
Konnor Andersen's avatar

Ooof, The nursing phishing with PTO is pretty brutal! One change I’m seeing in security awareness lately is the trainings via AI generated podcasts and honestly with podcast growth lately I think that is really smart!

Zero Drama Security's avatar

Love the title because it captures 3 very different problems. The part that stuck with me most was the OAuth compromise exposing Salesforce data, because I keep seeing identity and delegated access treated as "convenience" features instead of governance decisions. When CRM data is reachable through a third-party connection for example, then a lot of questions should arise: who approved the access, what data path it opened, how quickly it can be reviewed or revoked, etc. I think that’s where privacy and security teams can add calm value and help not overreacting.

No posts

Ready for more?