Episode

Why access brokers have stubbornly remained successful

Podcast
Safe Mode Podcast
Published
May 14, 2026
Duration seconds
1907
Processing state
not_requested
Canonical source
https://soundcloud.com/podcast-defensescoop-com/why-access-brokers-have
Audio
https://feeds.soundcloud.com/stream/2320620554-podcast-defensescoop-com-why-access-brokers-have.mp3
JSON
/v1/public/podcasts/safe-mode-podcast-6421323/episodes/why-access-brokers-have-stubbornly-remained-successful
Markdown
/podcast/safe-mode-podcast-6421323/why-access-brokers-have-stubbornly-remained-successful.md

Actions

  • POST https://stenobird.com/v1/public/podcasts/safe-mode-podcast-6421323/episodes/why-access-brokers-have-stubbornly-remained-successful/transcription-requests
    Idempotently request low-priority transcript generation for this episode.
  • GET https://stenobird.com/podcast/safe-mode-podcast-6421323/why-access-brokers-have-stubbornly-remained-successful.md
    Read the agent-friendly Markdown representation of this episode resource.

Summary

Anna Pham of Huntress joins Safe Mode to discuss the current landscape of initial access brokers and how their tactics continue to support ransomware operations. She explains that attackers are still finding success with drive-by downloads, Trojanized installers, fake browser updates, click-fix attacks, exposed RDP, VPN weaknesses, and vulnerable edge devices. The conversation also covers how access is monetized, what defenders can look for before ransomware deployment, and why limited endpoint visibility often leaves organizations exposed. Fam emphasizes that basic cyber hygiene still matters: close exposed ports, enforce MFA, use complex passwords, apply least privilege, patch systems, and maintain broad visibility across the environment. In our reporter chat, Greg talks with Matt Kapko about the security incident that impacted Canvas.