Episode

They don't break in, they log in. What's an enterprise to do?

Podcast
Risky Business Features
Published
Mar 12, 2026
Duration seconds
1922
Processing state
not_requested
Canonical source
https://risky.biz/RBFEATURES6/
Audio
https://dts.podtrac.com/redirect.mp3/media3.risky.biz/RBFEATURES6.mp3
JSON
/v1/public/podcasts/risky-business-features-7716365/episodes/they-don-t-break-in-they-log-in-what-s-an-enterprise-to-do
Markdown
/podcast/risky-business-features-7716365/they-don-t-break-in-they-log-in-what-s-an-enterprise-to-do.md

Actions

  • POST https://stenobird.com/v1/public/podcasts/risky-business-features-7716365/episodes/they-don-t-break-in-they-log-in-what-s-an-enterprise-to-do/transcription-requests
    Idempotently request low-priority transcript generation for this episode.
  • GET https://stenobird.com/podcast/risky-business-features-7716365/they-don-t-break-in-they-log-in-what-s-an-enterprise-to-do.md
    Read the agent-friendly Markdown representation of this episode resource.

Summary

In this podcast James Wilson chats with Brad Arkin about how enterprises can better deal with attackers logging in with valid credentials. Stolen identities, weak special-use credentials, and over-scoped API keys are the new zero-day and they’re abundantly available to attackers. Sadly, the solution here isn’t as simple as deploying phishing resistant MFA. Fixing this takes an enterprise identity strategy.