SonicWall, MFA Bypass, IABs: Why Patched Devices Are Still Handing Attackers Initial Access episode artwork

EPISODE · Jun 3, 2026 · 20 MIN

SonicWall, MFA Bypass, IABs: Why Patched Devices Are Still Handing Attackers Initial Access

from ShadowTalk: Powered by ReliaQuest

Your team patches the device. The firmware version matches the advisory. The ticket closes. The device comes off the remediation queue. What your workflow never tracked is that the advisory also required six manual LDAP configuration steps — and without them, the authentication bypass still works. An initial access broker authenticated through the VPN, reached a domain-joined file server, and was gone in under 40 minutes. Your dashboard still showed a clean queue.With initial access brokers operating on disciplined, sub-hour timelines and patch-management workflows built around a single completion step, defenders are closing tickets on devices that are still wide open.Join hosts Tehman and John as they discuss:How a firmware update can still leave a device fully exploitableHow initial access brokers progressed their attack in under 40 minutesWhy teams that prioritize from a single vulnerability score alone are behind Two questions your organization should be asking right now:Does your patch-management workflow include a separate item for post-patch manual configuration requirements?When CISA, NVD, and the vendor publish different CVSS scores for the same CVE, does your vulnerability-management policy specify which authority takes precedence — and does it supplement static scoring with a dynamic signal like EPSS? Tune in for expert insights, practical takeaways, and the full threat report: https://linktr.ee/ReliaQuestShadowTalkTehman Tariq: Sr. Manager of Cyber Operations at ReliaQuest. He has spent a majority of my career leading our Incident Response, Security Architecture, and Detection teams. As well has working hand in hand with CISOs to introduce automation allowing for the maturity of their security programs.John Dilgen: John Dilgen is a Cyber Threat Intelligence Analyst at ReliaQuest, where he specializes in researching cyber threats impacting ReliaQuest customers. With a strong technical background, he previously served as an Incident Response Analyst and Trainer at ReliaQuest. 

Episode metadata supplied by the publisher feed · Published Jun 3, 2026

Embed this episode

Your team patches the device. The firmware version matches the advisory. The ticket closes. The device comes off the remediation queue. What your workflow never tracked is that the advisory also required six manual LDAP configuration steps — and without them, the authentication bypass still works. An initial access broker authenticated through the VPN, reached a domain-joined file server, and was gone in under 40 minutes. Your dashboard still showed a clean queue. With initial access brokers ...

Distinct summary based on available episode metadata or transcript content.

NOW PLAYING

SonicWall, MFA Bypass, IABs: Why Patched Devices Are Still Handing Attackers Initial Access

0:00 20:51

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of ShadowTalk: Powered by ReliaQuest?

This episode is 20 minutes long.

When was this ShadowTalk: Powered by ReliaQuest episode published?

This episode was published on June 3, 2026.

Can I download this ShadowTalk: Powered by ReliaQuest episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!