


Episode description:
Show notes:
In this special interview episode, Adrian and Alexandre sit down with Alex Pinto, lead author of the Verizon Data Breach Investigations Report, to walk through the 2026 edition before the broader industry has fully digested it. Pinto explains why the 2026 dataset, with 31,850 incidents and 22,624 confirmed breaches contributed by over 100 organizations in 145 countries — is the most statistically rigorous breach corpus in the industry.
Tenchi Security is a 2026 contributor, providing the survival-analysis dataset behind the report's new look at third-party MFA and cloud privilege exposures. Alex Sieira walks through what the curves actually mean: half of MFA findings get fixed in seven days, but 45% of cloud privilege management findings are still open a year after discovery.
The conversation digs into the headline shifts: vulnerability exploitation has now overtaken credential abuse as the most common initial access vector. Third-party involvement in breaches has climbed from 30% last year to 48% this year, and the median time to fully remediate CISA KEV findings slipped from 32 to 43 days.
Then Pinto unveils what will probably be the most-talked-about new section of the 2026 report: Verizon analyzed an anonymized dataset from Anthropic. The data includes analysis of nearly 800 threat actors, maps their prompt activity to MITRE ATT&CK techniques, and cross-references it against MITRE's software database. The DBIR folks immediately think to ask the data: “are attackers using LLMs for novel techniques, or for things every EDR already catches?”
The trio close out by debating Sieira's hypothesis that the metric to watch isn't total CVE volume — it's the percentage of vulnerabilities with reliable working exploits, which is the variable AI is most likely to move — and Pinto makes the case that vulnerability management is becoming a crisis-management discipline rather than a dashboard-watching one.
References:
- The 2026 Verizon Data Breach Investigations Report (DBIR): https://www.verizon.com/business/resources/reports/dbir/
- Sieira and Pinto's RSA 2026 talk on how cloud-hyperscaler UX design impacts security outcomes https://path.rsaconference.com/flow/rsac/us26/FullAgenda/page/catalog/session/1755192044047001WRoa
- The Vercel Breach: https://cyberscoop.com/vercel-security-breach-third-party-attack-context-ai-lumma-stealer/
- The British Library breach write-up Adrian cited as a candid post-incident report (their "Learning Lessons" document): https://www.bl.uk/home/british-library-cyber-incident-review-8-march-2024.pdf


