Cloud Security Podcast by Google

EP268 Weaponizing the Administrative Fabric: Cloud Identity and SaaS Compromise in M Trends 2026

Mar 23, 2026
Scott Runnels, Mandiant incident responder with hands-on IR experience, and Kelli Vanderlee, senior threat analyst at Mandiant, discuss identity as the new perimeter and how attackers weaponize admin fabrics. They cover rapid attacker collaboration, identity and SaaS compromise trends, voice phishing in the GenAI era, malicious open-source packages, malware using local AI, and practical detection and response strategies.
Ask episode
AI Snips
Chapters
Books
Transcript
Episode notes
ADVICE

Make Security An Enabler Not A Blocker

  • Make security an enablement partner so users come to you instead of doing shadow IT.
  • Turn users into assets by integrating with teams, offering services, and making security the first stop for requests.
ADVICE

Require Out Of Band Checks For Voice Requests

  • Update authorization processes to require out-of-band verification for urgent requests that come via voice.
  • Educate users to hang up and call known numbers when CEOs request unusual actions like bulk gift card purchases.
INSIGHT

Identity Is The New Perimeter

  • Identity and SaaS integrations are the modern perimeter and offer a force multiplier for attackers.
  • Compromising one identity or SaaS app lets attackers spider into third-party integrations and administrative fabric across clouds.
Get the Snipd Podcast app to discover more snips from this episode
Get the app