What happens in the five days between a ransomware group buying access and burning your organization down? In this webinar, Abstract Security's Chief Threat Research Officer Aaron Shelmire and Director of Threat Engineering Justin Borland break down their findings from the Priced to Move report — a deep look at the initial access broker (IAB) ecosystem and what it means for defenders.
Topics covered:
- What initial access brokers are and how the cybercrime market has matured into tiered, specialized roles
- Why the most common credential pair found across 30,000 compromised devices was user/user — and what that means for your hygiene posture
- The shrinking time-to-exploit window, and how AI is accelerating weaponization of CVEs
- What a SOC actually needs in place to make use of that 5-day window — and what to do when the window is an hour or less
- The limits of MFA: fatigue attacks, session cookie hijacking, and why FIDO keys matter
- What Aaron and Justin are watching heading into the rest of 2026: SaaS supply chain risk, OAuth token replay, and the growing attack surface of third-party app integrations