Access the full text logs of this transmission for compliance and review purposes.
00:00:01:06 – 00:00:07:19
Actual
Welcome to Status Secure, the weekly Cyberthreat briefing for executives who refuse to operate in the blind.
00:00:07:21 – 00:00:20:08
Actual
Hosted by the watcher six collective, uniting former Army Special Forces and Naval Special Warfare communications operators alongside an industry leading CISO nominated for cybersecurity. Woman of the world.
00:00:20:10 – 00:00:27:05
Actual
We cut through the noise and give you the operational intelligence you need for mission success in a hostile digital environment.
00:00:27:07 – 00:00:28:10
Actual
The enemy is listening.
00:00:28:13 – 00:00:32:02
Actual
Is your status secure?
00:00:32:04 – 00:01:01:16
Actual
Welcome to Status Secure. Today we’re covering how AI is accelerating the speed at which attackers find and exploit vulnerabilities. The window between a flaw going public and it being weaponized is collapsing. And this is a curve catalog. The single most useful free resource most organizations still aren’t using to prioritize what to fix. And then we’re going to get into the big one for today, a field guide to Threat intelligence sources, where you can actually go to get reliable Intel without just randomly signing up for every free feed on the internet.
00:01:01:18 – 00:01:09:06
Actual
So let’s start with the speed problem. What’s changing about how fast vulnerabilities are getting exploited, and why is AI the accelerant?
00:01:09:06 – 00:01:35:20
CISO
Yeah, I mean, the, the gap between a vulnerability being disclosed and being exploited in the wild is shrinking, and attackers now weaponized faster than many orgs can patch. I mean, this was always this was always a problem before, but now it’s it’s becoming an even, you know, it’s increasing. That gap is getting bigger and bigger. So AI tools accelerate the discovery of software flaws and the creation of working exploits.
00:01:35:20 – 00:02:01:11
CISO
Right. So lowering the skill floor and raising the speed for attackers. So they’re finding these vulnerabilities faster then, you know, they’re getting patched. And that’s really the, the big issue here in, before it was very common ground. It took them a while to find the vulnerabilities, but in the meantime patches were coming out. And then, you know, companies could patch them before the attackers could, exploit them.
00:02:01:13 – 00:02:33:05
CISO
Well, that’s that’s changing, in 2026. So this year, Senator Mark Warner introduced to combat Emerging Threats to Critical Infrastructure Act. Then it’s explicitly citing concern that I could accelerate the discovery and exploitation of software flaws, plus AI supply chain vulnerabilities, deepfakes and quantum enabled attacks on cryptography. Right? So every sector runs the same software stack. A fast, weaponized TV in a common library or appliance hits healthcare, care, con tech, and finance simultaneously.
00:02:33:07 – 00:02:59:12
CISO
Do you remember, is it CrowdStrike? They it wasn’t a security like it wasn’t a vulnerability, but basically they had a change management. They they had they had, introduced an an issue into their release. Right. And it impacted the world, the globe. Can you imagine a vulnerability, right, that an attacker finds that is the same. It has the same impact, right.
00:02:59:14 – 00:03:19:22
CISO
So the defensive problem is no longer are we aware of vulnerabilities. It’s can we prioritize and act faster than an AI accelerated attacker that makes good threat intelligence the difference between patching the right thing today and the wrong thing next week? Because I mean, there’s the list is huge. So where do you start as a company, you know, how do you prioritize it?
00:03:20:00 – 00:03:40:15
Actual
Well, yeah. And that speed problem is exactly why our second our second topic today matters because you can’t just patch everything. Right. So you have to know what’s actually being exploited right now. I mean that’s what this is the kind of catalog is. Can you walk us through it because it’s free? It’s authoritative. And a lot of organizations still aren’t using it.
00:03:40:17 – 00:04:12:06
CISO
Yeah. So the CSR is the known Exploited Vulnerabilities catalog. It’s a free, authoritative, continuously updated list of vulnerabilities confirmed to be actively exploited in the wild right, published by the US Cybersecurity Infrastructure Security Agency. So that’s that’s CSR. So, it’s different from a CB list because thousands of CVEs are published. CEB tells you, the ones attackers are actually using right now, it can create an impossible patch backlog into a range pirate that we and I mentioned that right.
00:04:12:08 – 00:04:36:15
CISO
If you go into Microsoft, Microsoft, like most companies, most large companies, will publish their CV list and then, you know, give you like, the patches. But you’re talking about, you know, thousands of different sites, thousands of CVEs on each of those sites. Right? So the Cam has rapidly become a default reference for vulnerability prioritization across both public and private sector teams.
00:04:36:21 – 00:04:58:14
CISO
It’s one of the highest quality free sources available. And, camp is one source, a free government. One. The back half of this, of this is we’re going to a full map of where reliable Intel comes from and how to use it without drowning in noise. I mean, if you look at all the places that you can look at, if you if you’ve ever started looking at threat Intel, you’re going to be overwhelmed.
00:04:58:15 – 00:05:05:10
CISO
I mean, it is there’s a ton of sources. And so it’s like which ones do you use which start with the CS at camp.
00:05:05:12 – 00:05:13:22
Actual
Yeah. And so on that note, what are three things, to do this week on the vulnerability speed problem before we get into the sourcing of this intelligence.
00:05:13:23 – 00:05:40:19
CISO
Well, I you know, first it’s, you know, the chemistry. So cross-reference your asset inventory against the cab. Right. Identify like what? You know, what inventory you actually have, against the cab and fix what’s confirmed. Exploited. First, you know, that’s the that’s the first thing to do. Next is, you know, cheat actively exploited as, a different severity class with a faster clock.
00:05:40:19 – 00:06:04:23
CISO
The new normal cycle, because the attacker’s clock is faster. Now, most people do like, critical, like, I think critical vulnerabilities within 30 days, these like you, you see, you see one of these on your, you know, in your environment just I would say within seven days or faster, you can and then know your attack surface, but you can’t prioritize Intel against assets you don’t know you have an asset.
00:06:04:23 – 00:06:16:09
CISO
Inventory is, precondition. We talked about this, you know, all the time. You need to know what was in your system. You know, within your environment, so you can actually, you know, protect it. Yeah.
00:06:16:10 – 00:06:36:13
Actual
Now, last point is the doorway into, our main conversation today. So knowing what’s being exploited is only useful if you have reliable sources telling you what’s happening out there. And this is where a lot of companies maybe are missing out, right? They either rely on nothing or they randomly sign up for a bunch of different free tools.
00:06:36:13 – 00:06:54:03
Actual
Kind of just a bunch of noise, maybe. So let’s build that map. Give us the field guide. Where does threat intelligence actually come from? What are the real categories of sources, and how does a company that isn’t, say, a fortune 500 company with their kind of budget maybe build this without wasting money or time? Yeah.
00:06:54:03 – 00:07:18:12
CISO
So, there’s, you know, that Intel isn’t just one thing. Like, you can’t just look at one, at one source. There’s actually four categories of sources. And so you need to, review each one. The first category is your government once you have free authoritative sources. Right. So we talked about the Cab and the FBI has info guard.
00:07:18:12 – 00:07:38:18
CISO
And if you’re if you’re not familiar with that program, you know, the FBI partners with private sector members across 16 critical infrastructure. So find out if you’re in one of those 16 critical infrastructure. Sign up for your local info guard. Right. I mean, there’s a background check and all that. So it’s not like they allow anybody in there.
00:07:38:20 – 00:08:01:14
CISO
And then you’ll get, you know, information directly from the FBI for your particular, sector. The miter attack, that one’s also free, you know, based on attacker tactics and techniques, that that one’s been around for a long time. Take a look at it. It’s very comprehensive. The second category is your, like, your ice ax, right?
00:08:01:14 – 00:08:24:08
CISO
So these are a specific sharing. So I talked about the, the info guard. This one is, you know, these are like, information sharing and analysis centers. They’re member based, sector specific. They trust communities. So, you know, the the major ones are like the FS Isac, which is a financial service, H Isac which is for health care, Isac electricity.
00:08:24:09 – 00:08:58:19
CISO
Right. So they’re across these are provide you know, these provide government intelligence information, such a relevant sharing. So it’s not just, from the government, but it’s also from, you know, the community itself. Third is open source platforms and free feeds, right? Yeah. The malware information sharing platform, that’s it’s, you know, the open source, things that are widely, like use is, you know, your open city alien vault attacks.
00:08:58:20 – 00:09:21:21
CISO
I would, you know, malware bazaar. You know, they’re high value, but free. And so, you know, a lot of times there’s a hidden cost, right? They’re difficult to, kind of figure out engineering time to run and tune it. So again, anything free? I be buyer beware. Okay. In that category, the fourth is, of course, commercial platforms.
00:09:21:21 – 00:09:44:11
CISO
Right. So these are vendors that provide threat Intel and you pay for it. You pay for them to do, you know, to cross-reference all of the, the categories and all of the information recorded. Future Mandi an advantage CrowdStrike Falcon intelligence and and now we threat stream threat connect I mean these are these are big names right. But there’s a lot of players in this space.
00:09:44:13 – 00:10:03:20
CISO
So take a look at them, and, and see if this is for, you know, if one of these commercial platforms is for you. These are mostly for larger organizations. When you have the budget right, you have the money. But if you’re a smaller, you know, you’ve got to build it yourself or you got to take a look because you have to hire someone.
00:10:03:20 – 00:10:27:12
CISO
You have to build it. Maybe it’s worth the time to look at these commercial like the, the vendors. Right. So these are these categories layer on each other. So free government sector Isac couple of high signal open sources. And then maybe, you know, you can talk to like one of the when the Intel vendors and maybe get a subscription and start small right.
00:10:27:12 – 00:10:29:09
CISO
And build up as you get bigger and bigger.
00:10:29:11 – 00:10:48:19
Actual
Yeah. Yeah. And that’s kind of that’s a good point. And, you know, my question on that is, so you’ve provided a map kind of a broad range of, of tools. And if I wanted to narrow and say, I’m, you know, I’m at a, I’m a tech company, spending, maybe I do have some budget to put into this.
00:10:48:21 – 00:10:55:15
Actual
How do I know which of these to pick, right. What separates us? The source that’s worth my time from the noise.
00:10:55:17 – 00:11:24:11
CISO
Yeah. In, a good source tells you where the data coming, you know, came from. What behavior was observed and how it relates to a real attack, not just a raw list of, you know, apps. You know, I would say, like, there’s a lot of noise if you start looking at threat Intel and all of the different feeds, and sources consuming multiple feeds with no, like, management layer, your analyst is going to get super overwhelmed.
00:11:24:13 – 00:11:52:09
CISO
I mean, just as a human. But you know, there’s AI now. Hey, this is where this is where I can be, you know, used for good. So, you know, somebody or something has to look at all that noise and make sense of it. So you need a layer that normalizes the duplicates and scores that what? That’s what the the tip, the threat intelligence platforms.
00:11:52:11 – 00:12:10:14
CISO
You know, that’s what they usually do for you, right. But you need that. You can’t just ingest like you can’t just have a person sitting there trying to look at multiple, you know, multiple feeds and multiple sources. It’s it’s just it’s overwhelming. It’s too much. Right. And then they’re going to miss. They’re going to miss the, the critical signals.
00:12:10:15 – 00:12:27:14
CISO
So a sector Isac feed well into your industry. It’s ten generic global feeds. Right. So massive. So as to your actual threat model and asset inventory. That’s the key. Don’t look at everything. Just look at what you, you know like take out your inventory and then match your inventory to the feed.
00:12:27:15 – 00:12:44:03
Actual
Got it. Yeah. And so before we skip to to the enter recover kind of the marching orders of our advice, let’s just riff on this a little bit. So you brought this up because every week we discuss, we get together and we, we chat about, hey, what do we want to talk about this week? Maybe there’s some current events going on.
00:12:44:05 – 00:13:02:05
Actual
And you brought this topic up of like, okay, threat Intel, sources and whatnot. So on to, you know, like off script here, walk me through like, why was that in your head? Why was this the topic you wanted to discuss? Any other sort of pieces of that that we haven’t touched on yet that you can just you can riff on a bit for us?
00:13:02:09 – 00:13:29:19
CISO
Sure. I mean, the vulnerabilities have been around for a long time. It’s I mean, it’s in is as soon as the first person who realized, okay, a long, long time in a long wait. What’s that? What’s that Star Wars thing that always, goes by a in a galaxy far away a long, long time ago way. You know, the internet was start, was born, and people started building things, right?
00:13:29:20 – 00:13:55:18
CISO
And it was open. It was open because everybody was so excited for the first bad actor, you know, realized that, hey, they could take advantage of what was being done. Hey. And, and so vulnerabilities and, and bad actors and threats. Right. They’ve been around since the beginning. You can’t have good and not have bad. Okay. So the, and I was thinking about that.
00:13:55:18 – 00:14:18:11
CISO
This is not gone away. It’s not like we got better and these vulnerabilities went away. I mean, even though we have a list of them, ain’t they? Didn’t. It’s not like, if you take a look at, you know, some recent, some recent attacks and, you know, some of the big ones, they came in through some kind of vulnerability, right?
00:14:18:13 – 00:14:44:09
CISO
If it wasn’t human, if it wasn’t, like social engineering, then then it’s it was through a vulnerability. Somebody didn’t patch something somewhere. And and it’s so like, it’s such an easy thing to close, but why doesn’t it happen? And it’s only going to get worse. That’s why I was thinking about it. Thank you. And especially with the what we saw, like I mentioned before, like with CrowdStrike, that was unintended.
00:14:44:09 – 00:14:55:23
CISO
And it wasn’t a back bad actor, which is a human, you know, a human error. But what if it was a bad actor? They’re going to take down the entire world, right, with one vulnerability. That’s it. That’s a possibility.
00:14:56:04 – 00:15:17:17
Actual
Now. Well, and that’s happened not I mean, not in like, that big scale, you know, terrifying event, maybe. But we’ve had, these events have happened where, like, Amazon web servers go down, right? And like, half the internet’s offline like that. This has happened. And so. Right. It’s good to stay ahead of it, ahead of the curve, you know, and having that Intel is helpful.
00:15:17:17 – 00:15:38:03
Actual
You know, what it makes me think of is, you know, kind of off topic, I guess back when I was in the military, we deployed. And you’re looking at your your little firebase, if you will, and you have your sectors and you have a plan mapped out to keep, to keep you secure. Right. And you’ll look at it and you’ll go, hey, there’s a gap here.
00:15:38:08 – 00:15:58:10
Actual
Like there’s a gap between these sectors of fire or there’s a gap in like our security perimeter. And why hasn’t anybody paid attention to it? Maybe we need to close it and have eyes on it because that’s that’s that like place that the enemy could just literally walk in and nobody’s nobody’s covering that. And it’s that’s kind of a more tangible example.
00:15:58:10 – 00:16:09:08
Actual
But that’s, that’s what I’m hearing with, with this kind of stuff. It’s going like, you know, making sure we close those, those gaps, but how can we close them if we don’t know where they are?
00:16:09:10 – 00:16:33:19
CISO
Yeah. I mean, and we talked about this too, which is you have to have the same goal, right. Because your security people are looking at that gap and saying, hey, you know, some attacker can come in here and and just, you know, get all of our people. And, but then you have like, I don’t know, like, you know, but then you have like these CEOs and executives and, you know, leaders who are like, you know, okay, thanks for telling me about the gap, but I don’t care about that.
00:16:33:19 – 00:16:55:15
CISO
I need to move faster to get to this, you know, to get to this over the over this ridge. Right. Like, which one do you do you do you put your resources towards moving everything to, you know, to, to that, that location up there or do you, you know, close this closest like, gap. Right. This hole that you see knowing that you’re going to be moving.
00:16:55:18 – 00:17:10:11
CISO
I mean, it’s, it’s it’s a it’s an interesting question, right. Like at the security level always we want to we want to close the gap. But then at the leadership level they’re always like, well yeah, but if we move fast enough, that gap won’t be there. Thank. Yeah.
00:17:10:13 – 00:17:32:17
Actual
Yeah. And I think it’s it’s the role of that leader. Right. It’s the reason why that person’s maybe the CEO or what have you. Because it’s their job to make a decision. Regardless of either decision is perfect or not. Right. They’ve they’ve got to make they’ve got to make those decisions. And most of the time, whatever decision they make, someone’s not going to be happy or something’s not going to get done, in order to move forward.
00:17:32:19 – 00:17:49:20
Actual
And so if you go back maybe to like the security person on this conversation, it’s your job to be like, ready. It’s your job to know this stuff. It’s your job to know where the vulnerabilities are, have a course of action, a plan of action in place and say, this is this is what the problem is. This is our solution.
00:17:49:20 – 00:17:59:17
Actual
Maybe this is what it cost. So on and so on and so on to be able to brief that leader so they can make a more, educated decision. And that’s just kind of the nature of it.
00:17:59:19 – 00:18:18:12
CISO
No, I, I yeah, absolutely. The, the one thing that I would say is a lot of security people talk from a security perspective. You get to talk for and this is unfortunate, but you got to talk from the business like if you’re a, if you’re a private sector profit, you know, profit organization, you have to you have to talk from that.
00:18:18:17 – 00:19:00:08
CISO
Right? Because I can tell you that executives like, well, it’s your job to keep, you know, to keep the, you know, to keep security in place. And, so you figure it out if you want that executive to be, you know, like, right, because you need their support and for them to kind of, build the culture from the top down, that security’s important, you’re going to have to talk to them in terms of revenue, Nate, in terms of money, like how does how does this going to how is this going to impact, like, you know, their bottom line and their speed to market their you know, and their desire for operational efficiency.
00:19:00:08 – 00:19:21:14
CISO
So there so so the the books, you know, so the the line like the the line, the in the ledger a is less like their cost, way less like you got to talk those that you know in those terms and most security professionals aren’t very good at that. They’re just talking about hey there’s a hole here. Yeah. There’s a hole.
00:19:21:16 – 00:19:21:19
CISO
Yeah.
00:19:21:20 – 00:19:43:19
Actual
That’s a good point in. Yeah, I think there’s, there’s two topics there. To if we can learn them. One is the revenue conversation like and don’t just like barge through the doors and say, give me $10 million to, you know, solve all these problems like it’s probably not going to happen. So understanding like realistic, like revenue in terms of what you’re trying to accomplish security wise.
00:19:43:19 – 00:20:05:00
Actual
But the other conversation too, can be a little bit more, reputational PR think of like, like LastPass was a good example. LastPass had, I forget, years ago they had some kind of breach or whatever, but basically they lost their reputation in the market and so many people drop them and switch to their competitor because of that.
00:20:05:00 – 00:20:22:10
Actual
And that’s a that’s another angle of like depending on what industry you’re in or what you’re doing, being able to pitch that like, hey, you know, if if this vulnerability gets exploited, it doesn’t just like, you know, they can’t. It’s not just that they’re going to steal information or whatever, you know, cause something bad to happen which will cost X amount of dollars to fix.
00:20:22:10 – 00:20:38:11
Actual
So that’s the revenue side. But the other side is depending on what you’re doing, you could also say, look, this could be this could be a relationship killer. And if you have any deals in the pipeline, like big deals going on and this happens, you might lose all of them all at once and and and lose current clients because of that.
00:20:38:11 – 00:20:53:03
Actual
So that’s another way of having that conversation. You know, but you obviously you can’t you can’t do that with every conversation otherwise. And you become like like the boy who cried wolf all the time. So there’s there is a little bit of a technique to it.
00:20:53:04 – 00:21:10:10
CISO
It is. I mean, it’s all about customer trust, right? That’s what happened to LastPass. They lost their customers trust me. Yeah. Yeah. You can’t say, hey, I’m I’m going to keep your passwords secure and then you can’t secure here without. Fine.
00:21:10:12 – 00:21:34:12
Actual
Yeah, exactly. So let’s get into this. Marching orders. So we covered the AI accelerated exploitation and the curve catalog at the top. We provided some resources, that you can use. Maybe some advice on how to narrow down what’s what’s for you. And some tips about, how to present to maybe the dealmaker in the conversation.
00:21:34:14 – 00:21:40:13
Actual
And so let’s see. So why don’t you walk us through the three marching orders, this week for what we’ve discussed?
00:21:40:14 – 00:22:05:12
CISO
Okay. Yeah, sure. I mean, the first one, the first order is lock in the free, authoritative baseline. Right. We talked about them like C6 Cav miter attack. You know, the. Oh, there’s like ocean. There’s, like, you know, 1 or 2 high signal open feeds, right? Yeah. So you don’t have any excuses here, you know, free, authoritative sources, right.
00:22:05:12 – 00:22:26:21
CISO
Second or, you know, the second order is join your such as trusted sharing community eight. You know, the Isaac’s wage. You know, there’s finir there’s 16 of them, you know, find the one that you’re in and join one because you need your community, because people, people see things. It’s it’s, see, you know, is it, you know, if you see something, tell.
00:22:26:22 – 00:22:47:05
CISO
Right. So these communities are all about that. If they see something they share, they tell. Right? So it doesn’t happen. So maybe it’ll only happen to one in the community and not to all. Mate. And this is a trusted layer because everybody wants, you know, everybody wants their sector to be successful. And then of course, decide build, you know, build, which is buying.
00:22:47:05 – 00:23:13:12
CISO
And this is, something that only you know, you can decide. You’re going to have to make that. And, you know, the pros, the cons, the cost. Right? The trade offs. So if you’re consuming more than a couple feeds, you know, you you need a, you know, a tent, you know, that translation layer, right? So whether you build it or you buy it, we, to normalize dedupe and and score all of the feeds.
00:23:13:16 – 00:23:36:16
CISO
Right? So match meshes spend to your threat model, right. Don’t buy you know, don’t buy a vendor just to ignore them. I’ve seen companies do that. They spend a lot of money purchasing these like, you know, these vendors, I give you really great threat Intel and then nobody sees it except for one analyst, and nobody hears about it except for some for a security analyst, you know, in the corner.
00:23:36:16 – 00:23:42:19
CISO
Right. Make sure that you’re actually incorporating it into your business process.
00:23:42:21 – 00:24:05:22
Actual
Oh. Got it. So I is in the time attackers need to weaponize a vulnerability. The CC curve catalog is the free anchor that tells you what to fix first. But knowing what to fix means having reliable intelligence in the field. Guide a simple start with free government sources. Join your sector’s trusted sharing community. Add some high signal open feeds only buy commercial when your threat model justifies it.
00:24:06:03 – 00:24:27:17
Actual
Don’t randomly sign up for noise. Remember, the adversary reads the public sources to and Watch the legal ground under the Intel sharing because it’s shifting. So mission success starts with knowing, you know, another thing that we also talked about too is knowing how to you have this Intel, you have this information, you see the threats, you know, maybe the solutions.
00:24:27:23 – 00:24:53:09
Actual
And also maybe, learning, maybe doing some study on how to appropriately pitch that to the decision maker. That’s also a helpful tool. Maybe we’ll have an episode on that. Right. So, yeah, mission success starts with knowing where your Intel comes from and acting on it faster than the other side. So trust but verify your own posture and, prioritize off curve.
00:24:53:09 – 00:24:59:23
Actual
Join your Isac, stand up for management layer of your feeds. Execute the standard, and we’ll see you next week.
00:25:00:01 – 00:25:03:18
Actual
Mission. Success isn’t about luck. It’s about preparation.
00:25:03:20 – 00:25:06:19
Actual
You’ve heard the Intel. Now go put it to use.
00:25:06:21 – 00:25:14:05
Actual
If you need to verify your security posture. I’ve established a secure line at watcher 6.com/secure.
00:25:14:07 – 00:25:17:07
Actual
Go there to get the briefing the enemy doesn’t want you to have.
00:25:17:09 – 00:25:20:15
Actual
We’ll see you next week. Until then, keep your head on a swivel.