Paul's Security Weekly (Audio) Back to (or Start) Fundamentals? - Rajesh Khazanchi - PSW #923
Apr 23, 2026
They unpack a Bluetooth tracker sent to a navy ship and risky serial-to-IP devices sitting in critical infrastructure. Regulation news forces MFA and asset inventories into the limelight. Conversations cover AI-driven vulnerability discovery, the persistent Mirai threat from unpatched routers, quantum crypto timing debates, preloaded used drives, and strategies for breach readiness and microsegmentation.
AI Snips
Chapters
Transcript
Episode notes
Design For Small Breaches Not Zero Breaches
- Breach readiness means designing to make incidents small, not impossible to prevent.
- Rajesh Khazanchi says microsegmentation and containment ensure a single compromised entity can't cascade across cloud, data center, or OT environments.
Segment To Stop Lateral Movement
- Segmentation limits lateral movement by granting each app or user only the exact access they need.
- Khazanchi recommends enforcing microsegmentation across data centers, cloud, applications and OT to block unfettered internal access.
Adversaries Prefer Approved Paths Over Loud Attacks
- Attackers increasingly use approved paths and stolen identities rather than noisy brute force.
- Khazanchi notes identity theft and credential compromise let adversaries move inside networks without breaking doors.
