The B2B Podcast Index
Index
All categories
MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
MethodologySubmit
Best of:MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
An independent project byFame
SearchBest episodesGuestsInsightsMethodologySubmit a podcast
Index/AI & Data/ShadowTalk: Powered by ReliaQuest
ShadowTalk: Powered by ReliaQuest artwork

SonicWall, MFA Bypass, IABs: Why Patched Devices Are Still Handing Attackers Initial Access

ShadowTalk: Powered by ReliaQuest · 2026-06-03 · 21 min

0:00--:--

Episode notes

Your team patches the device. The firmware version matches the advisory. The ticket closes. The device comes off the remediation queue. What your workflow never tracked is that the advisory also required six manual LDAP configuration steps - and without them, the authentication bypass still works. An initial access broker authenticated through the VPN, reached a domain-joined file server, and was gone in under 40 minutes. Your dashboard still showed a clean queue. With initial access brokers operating on disciplined, sub-hour timelines and patch-management workflows built around a single completion step, defenders are closing tickets on devices that are still wide open. Join hosts Tehman and John as they discuss: How a firmware update can still leave a device fully exploitable How initial access brokers progressed their attack in under 40 minutes Why teams that prioritize from a single vulnerability score alone are behind Two questions your organization should be asking right now: Does your patch-management workflow include a separate item for post-patch manual configuration requirements?

More from ShadowTalk: Powered by ReliaQuest

All episodes →
  • How Hackers Are Using AI Right Now: Faster Attacks, Smarter Malware, and a New Arms Race73 / 100
  • Klue, Kali365, OAuth: When the Front Door Is a Trusted Integration
  • ShinyHunters' Expanding Toolkit: Oracle PeopleSoft Zero-Day Exploitation and the BreachForums Defense Gaps
  • China-Linked Cyber Espionage: How OP-512 Exploited Legacy IIS Servers and Evaded Detection
  • Device Code, OAuth, PhaaS: How Session Token Theft is Breaking the Phishing Playbook
Explore the best B2B AI & Data podcasts →
All ShadowTalk: Powered by ReliaQuest episodes →