Episode

Securing the Workspace Attackers Already Live In with Rajan Kapoor

Podcast
Hacker Valley Studio
Published
Feb 19, 2026
Duration seconds
2309
Processing state
not_requested
Canonical source
https://HackerValleyStudio.podbean.com/e/securing-the-workspace-attackers-already-live-in-with-rajan-kapoor/
Audio
https://mcdn.podbean.com/mf/web/gxby3kqq382fbbwu/HVS26_EP415_Material_Security9h1tg.mp3
JSON
/v1/public/podcasts/hacker-valley-studio-344898/episodes/securing-the-workspace-attackers-already-live-in-with-rajan-kapoor
Markdown
/podcast/hacker-valley-studio-344898/securing-the-workspace-attackers-already-live-in-with-rajan-kapoor.md

Actions

  • POST https://stenobird.com/v1/public/podcasts/hacker-valley-studio-344898/episodes/securing-the-workspace-attackers-already-live-in-with-rajan-kapoor/transcription-requests
    Idempotently request low-priority transcript generation for this episode.
  • GET https://stenobird.com/podcast/hacker-valley-studio-344898/securing-the-workspace-attackers-already-live-in-with-rajan-kapoor.md
    Read the agent-friendly Markdown representation of this episode resource.

Summary

Your email gateway isn't enough anymore, attackers are already inside the workspace through OAuth apps, browser extensions, and account takeover. In this episode, Ron sits down with Rajan Kapoor, VP of Security at Material Security, to break down the real risks hiding inside Google Workspace and Microsoft 365. They cover how phishing has evolved into full-blown business email compromise, why malicious OAuth apps are the new favorite attack vector, and what security teams, especially lean ones, can do right now to lock down their cloud workspace. Rajan also drops practical advice on passkeys, document sharing hygiene, and why data lifecycle management is a problem no one is solving well enough. Impactful Moments00:00 – Introduction03:30 – The current state of phishing05:30 – Outbound email compromise risk09:30 – OAuth apps as attack vectors15:00 – AI agents accessing your workspace16:00 – Prompt injection is the new SQL injection18:00 – Allow listing apps immediately24:30 – Google Workspace vs Microsoft 365 security27:30 – Custom detections require API expertise28:00 – Why passkeys matter right now32:00 – Data lifecycle management for shared docs LinksConnect with our guest, Rajan Kapoor, on LinkedIn: https://www.linkedin.com/in/rajankkapoor/ Learn more about Material Security: https://material.security ___Become a sponsor of the show to amplify your brand: https://hackervalley.com/work-with-us/ Check out our upcoming events: https://www.hackervalley.com/livestreams Love Hacker Valley Studio? Pick up some swag: https://store.hackervalley.com