Illumio is a Customers’ Choice in the 2026 Gartner Peer Insights for Network Security Microsegmentation.

The Zero Trust Hub

Trends, insights, and resources for today's cybersecurity leaders. Updated weekly.

Subscribe on LinkedIn
May 25, 2026
Want more Zero Trust segmentation trends, insights, and resources?
Explore past editions
The Monday Microsegment for the week of 5/25/2026
NEWS
Microsoft MDASH: The Cyber Arms Race Hits at Machine Speed

In Forbes, Illumio CEO and founder Andrew Rubin warns that AI-powered cyberattacks are moving at machine speed as Microsoft’s MDASH system outperformed Anthropic’s Mythos in vulnerability discovery. Security must shift from prevention alone to breach containment strategies.

Read more
NEWS
AI Is Collecting on Years of Wireless Cybersecurity Debt

In Network World, John Kindervag says AI-powered attacks are exposing years of neglected wireless security fundamentals — and the window to act is closing. He argues that Zero Trust and segmentation remain critical to stop attackers from moving across WiFi, IoT, and OT networks.

Read more

What a Three-Time DEF CON Champion Hacker Taught Me About Zero Trust

Raghu Nandakumara
VP, Industry Strategy

If someone spent 20 minutes researching you online right now, what would they find? And what could they use to build a successful cyberattack against you?  

In my recent discussion with Rachel Tobac, CEO of Social Proof Security and three-time DEF CON Social Engineering Competition champion, she answered that question live — using me as the target.  

In under 20 minutes, start to finish, she uncovered my contact details, found breach data with a plaintext password, cloned my voice, created a real-time deepfake, and built a spear-phishing email built from my own social media.  

Three years ago, that kind of reconnaissance took close to a hundred hours. But AI has collapsed every stage of the attack chain. When the attack is that fast and that personalized, perimeter defenses and behavioral training aren’t enough on their own.  

Zero Trust was designed for exactly this reality. The architectural decisions that follow from it determine how much damage a twenty-minute dossier can actually do inside your environment.

From 100 hours to 20 minutes: what AI has done to the attack chain

Rachel was precise about what AI has changed and what it has not.  

The tactics are the same ones Robert Cialdini documented decades ago, including authority, urgency, reciprocity, and social proof.  

What AI has done is collapse the time cost. You can clone a voice from a minute of audio. You can generate a real-time deepfake with no specialist equipment. Attacks are faster, more scalable, and far more believable than they were three years ago.

This matters because organizations are expanding their AI footprint under the same “secure it later” assumption. Agents are going into production without identity validation. Sensitive data is flowing in without access controls.  

Every unsecured AI tool hands the adversary more to work with. Zero Trust has to extend to the AI you deploy internally, not just the threats coming from outside.

Why security training can’t keep pace with an automated attack chain

During our discussion, Rachel found on my public social media that I’m a devoted listener of The Grade Cricketer. Using that information, she built a phishing email impersonating two of its hosts inviting me to appear in a listener interview.  

My honest reaction was that I would’ve clicked it immediately. When the attack pretext is hyper-personalized, anyone’s trained instinct to pause can get overwhelmed. Even the best training has limits that grow as AI raises the believability ceiling of attacks.

When the attacker is already inside, Zero Trust stops them

Most security strategies focus on keeping attackers out. Zero Trust focuses on what happens when they get in. When I asked Rachel what frustrates her most as a hacker, she pointed to Zero Trust controls, especially microsegmentation.

Microsegmentation splits the network into isolated zones. A compromised account can't roam freely across systems. An attacker who gets in through a phishing link or a cloned voice call hits a wall fast. The blast radius stays small by design, not by luck, and it works even if no one spotted the attack.

The same logic applies to AI tools. Every agent that assumes trust instead of verifying it is an opening. Zero Trust for internal AI means the same rules apply: verify first, limit access, and contain the damage if something goes wrong.

Get your architecture ready before the next AI-generated attack

Watching Rachel build that attack against me in under twenty minutes was a reminder that the threat has moved faster than most security architectures have. The tools are cheap, the data is public, and the time investment is minimal.  

This is the environment CISOs are operating in today. And it’s exactly the environment Zero Trust was designed for. It’s a practical architecture built around a simple premise. Assume the attacker will get in, make sure they can’t go far, and ensure your organization can recover fast.  

Rachel’s demo showed what the attack looks like when it works. Zero Trust is the answer to what happens next.

Read more

Vulnerabilities Risk Rise

Attackers exploited vulnerabilities more than ever based on findings in this year’s Verizon Data Breach Investigations Report (DBIR), jumping from 20% to 31% as the dominant initial access vector. That sharp rise pushed it well ahead of phishing and credential abuse, which signals a major shift in how attackers are breaking in. Credential abuse, once the top technique, dropped significantly to 13%, though part of that decline reflects the addition of pretexting as a newly tracked category. The data shows attackers increasingly favor exploiting vulnerabilities over more traditional identity-focused methods.

Get the industry’s first vendor-neutral Zero Trust certification.

The Hub Contributors

John Kindervag

Chief Evangelist

Read now

Raghu Nandakumara

Vice President, Industry Strategy

Read now

Gary Barlet

Public Sector CTO

Read now

Trevor Dearing

Director of Critical Infrastructure Solutions

Read now

Michael Adjei

Director, Systems Engineering

Read now

Christer Swartz

Director of Industry Solutions

Read now

Aishwarya Ramani

Sr. Solutions Marketing Manager

Read now

Trupti Shiralkar

Director of Product Security

Read now

Scott Smith

Analyst Relations Director

Read now