Klue's OAuth compromise exposed Salesforce data across the security vendor bench; Accenture spends $4.175B on Dragos, runZero, and NetRise; Cisco picks up WideField for Splunk's agentic SOC.
Ooof, The nursing phishing with PTO is pretty brutal! One change I’m seeing in security awareness lately is the trainings via AI generated podcasts and honestly with podcast growth lately I think that is really smart!
Love the title because it captures 3 very different problems. The part that stuck with me most was the OAuth compromise exposing Salesforce data, because I keep seeing identity and delegated access treated as "convenience" features instead of governance decisions. When CRM data is reachable through a third-party connection for example, then a lot of questions should arise: who approved the access, what data path it opened, how quickly it can be reviewed or revoked, etc. I think that’s where privacy and security teams can add calm value and help not overreacting.
Ooof, The nursing phishing with PTO is pretty brutal! One change I’m seeing in security awareness lately is the trainings via AI generated podcasts and honestly with podcast growth lately I think that is really smart!
Love the title because it captures 3 very different problems. The part that stuck with me most was the OAuth compromise exposing Salesforce data, because I keep seeing identity and delegated access treated as "convenience" features instead of governance decisions. When CRM data is reachable through a third-party connection for example, then a lot of questions should arise: who approved the access, what data path it opened, how quickly it can be reviewed or revoked, etc. I think that’s where privacy and security teams can add calm value and help not overreacting.