
Cloud Security Podcast by Google EP268 Weaponizing the Administrative Fabric: Cloud Identity and SaaS Compromise in M Trends 2026
Mar 23, 2026
Scott Runnels, Mandiant incident responder with hands-on IR experience, and Kelli Vanderlee, senior threat analyst at Mandiant, discuss identity as the new perimeter and how attackers weaponize admin fabrics. They cover rapid attacker collaboration, identity and SaaS compromise trends, voice phishing in the GenAI era, malicious open-source packages, malware using local AI, and practical detection and response strategies.
AI Snips
Chapters
Books
Transcript
Episode notes
Make Security An Enabler Not A Blocker
- Make security an enablement partner so users come to you instead of doing shadow IT.
- Turn users into assets by integrating with teams, offering services, and making security the first stop for requests.
Require Out Of Band Checks For Voice Requests
- Update authorization processes to require out-of-band verification for urgent requests that come via voice.
- Educate users to hang up and call known numbers when CEOs request unusual actions like bulk gift card purchases.
Identity Is The New Perimeter
- Identity and SaaS integrations are the modern perimeter and offer a force multiplier for attackers.
- Compromising one identity or SaaS app lets attackers spider into third-party integrations and administrative fabric across clouds.



