Securing the Workspace Attackers Already Live In with Rajan Kapoor

Securing the Workspace Attackers Already Live In with Rajan Kapoor

Your email gateway isn't enough anymore, attackers are already inside the workspace through OAuth apps, browser extensions, and account takeover.

In this episode, Ron sits down with Rajan Kapoor, VP of Security at Material Security, to break down the real risks hiding inside Google Workspace and Microsoft 365. They cover how phishing has evolved into full-blown business email compromise, why malicious OAuth apps are the new favorite attack vector, and what security teams, especially lean ones, can do right now to lock down their cloud workspace. Rajan also drops practical advice on passkeys, document sharing hygiene, and why data lifecycle management is a problem no one is solving well enough.

Impactful Moments 00:00 – Introduction 03:30 – The current state of phishing 05:30 – Outbound email compromise risk 09:30 – OAuth apps as attack vectors 15:00 – AI agents accessing your workspace 16:00 – Prompt injection is the new SQL injection 18:00 – Allow listing apps immediately 24:30 – Google Workspace vs Microsoft 365 security 27:30 – Custom detections require API expertise 28:00 – Why passkeys matter right now 32:00 – Data lifecycle management for shared docs

Links Connect with our guest, Rajan Kapoor, on LinkedIn: https://www.linkedin.com/in/rajankkapoor/

Learn more about Material Security: https://material.security

___ Become a sponsor of the show to amplify your brand: https://hackervalley.com/work-with-us/

Check out our upcoming events: https://www.hackervalley.com/livestreams

Love Hacker Valley Studio? Pick up some swag: https://store.hackervalley.com

Det här avsnittet är hämtat från ett öppet RSS-flöde och publiceras inte av Podme. Det kan innehålla reklam.

Avsnitt(438)

The AI Already Inside Your Company with Russell Spitler & Richard Penshorn

The AI Already Inside Your Company with Russell Spitler & Richard Penshorn

A year ago, the average employee held about 30 OAuth grants. Today that number has risen to 88, and it isn't slowing down. Ron sits down with Russell Spitler, co-founder and CEO of Nudge Security, and...

25 Aug 35min

Humans First: Adobe's Rule for Building AI Security Tools with John Gillis

Humans First: Adobe's Rule for Building AI Security Tools with John Gillis

Imagine how much investigation time your SOC could get back if the busywork just disappeared. Ron sits down with John Gillis, Staff Security AI Engineer at Adobe, who built an in-house AI investigatio...

19 Aug 34min

Let AI Do More Without Surrendering Your Judgment with Jen Easterly

Let AI Do More Without Surrendering Your Judgment with Jen Easterly

Fresh off the showroom floor at Black Hat 2026, Ron brings back some hot takes from the crowd. Nearly every booth he visited, including the Exaforce booth, was pushing in the same direction. Trust in ...

14 Aug 23min

Post-Quantum Cryptography: What Every Organization Needs to Know with Michael Fasulo

Post-Quantum Cryptography: What Every Organization Needs to Know with Michael Fasulo

What if the encrypted traffic flowing across the internet right now (emails, files, logins) is already being quietly collected and stored by someone waiting for the day they can finally crack it open?...

12 Aug 30min

Stop Defending the Edge: How to Rethink Your Mobile Security with Jared Shepard

Stop Defending the Edge: How to Rethink Your Mobile Security with Jared Shepard

What if the biggest risk to your organization isn't the device that gets lost, but the data that lives on it? Ron Eddings sits down with Jared Shepard, Founder and CEO of Hypori, whose path ran from h...

7 Aug 38min

Inside Conti: The Ransomware Gang That Ran Like a Company with Geoff White

Inside Conti: The Ransomware Gang That Ran Like a Company with Geoff White

What does the world's most prolific cybercrime operation look like from the inside? And why does it operate suspiciously like a mid-sized tech company, complete with HR headaches, salary negotiations,...

28 Juli 34min

What AI Agents Should Own in Your SOC, And What Happens If You Wait with Tim Leehealey

What AI Agents Should Own in Your SOC, And What Happens If You Wait with Tim Leehealey

What happens when the adversary moves at machine speed, and your SOC is still responding at human speed? Why does nearly every security team say AI should handle L1 work, while 64% of organizations st...

21 Juli 35min

We Shipped a Tool That Acts Like You. Meet Interceptor.

We Shipped a Tool That Acts Like You. Meet Interceptor.

Think about everything you could accomplish if you don’t have to be the one driving your browser. In this solo episode, Ron Eddings introduces Interceptor, Hacker Valley Media's first piece of softwar...

14 Juli 30min

Populärt inom Utbildning

historiepodden-se
det-skaver
rss-bara-en-till-om-beroende-medberoende
nu-blir-det-historia
harrisons-dramatiska-historia
not-fanny-anymore
rss-viktmedicinpodden
johannes-hansen-podcast
roda-vita-rosen
allt-du-velat-veta
rikatillsammans-om-privatekonomi-rikedom-i-livet
i-vantan-pa-katastrofen
rss-ar-det-rimligt
rss-max-tant-med-max-villman
rss-basta-livet
sa-in-i-sjalen
rss-foraldramotet-bring-lagercrantz
sektledare
rss-traningsklubben
rss-autismandan