EPISODE · Aug 6, 2026 · 16 MIN
Dark Perimeter: "The Forty-Eight Hour Window"
from Dark Perimeter: True Cybersecurity Stories
Eighty-eight percent. In the first half of 2026, according to CrowdStrike's 2026 Threat Hunting Report published August 3, that is the share of intrusions following a public vulnerability disclosure that occurred within forty-eight hours of that disclosure. Cole Drayden, Dr. Elliott Vance and Marcus Hale work through three stories from a single week and argue they are one story: The collapsed window. What the CrowdStrike number measures and what it does not, plus React2Shell exploited inside twenty-four hours by groups CrowdStrike tracks as Vault Panda and Genesis Panda. The incomplete patch. N-able N-central CVE-2026-18577, an authentication bypass created by an incomplete fix for CVE-2026-18556. N-able confirmed a limited number of customers compromised on August 2; CISA added it to the Known Exploited Vulnerabilities catalog on August 3 with a federal deadline of August 6. Why an RMM platform is the most valuable position in a managed environment, and why persistence via a documented default support account defeats most detection. CHAINDROP. The self-propagating npm worm analysed by Elastic Security Labs on August 4, spreading through publishing rights rather than network topology, harvesting cloud, CI, Vault and AI-provider credentials, and pulling its exfiltration endpoint from an Ethereum smart contract at runtime. The practical half: how to inventory the vendors holding standing privileged access into your environment, why time-to-remediate against KEV beats a patch compliance percentage, naming your compensating controls out loud in the risk acceptance, and killing long-lived credentials in build pipelines. Attribution in this episode is attributed. Vendor assessments are identified as vendor assessments.Support the show
Embed this episode
What this episode covers
Eighty-eight percent. In the first half of 2026, according to CrowdStrike's 2026 Threat Hunting Report published August 3, that is the share of intrusions following a public vulnerability disclosure that occurred within forty-eight hours of that disclosure. Cole Drayden, Dr. Elliott Vance and Marcus Hale work through three stories from a single week and argue they are one story: The collapsed window. What the CrowdStrike number measures and what it does not, plus React2Shell exploited insi...
NOW PLAYING
Dark Perimeter: "The Forty-Eight Hour Window"
No transcript for this episode yet
Similar Episodes
No similar episodes found.
Similar Podcasts
No similar podcasts found.