
Threat Vector by Palo Alto Networks Don't Leave Them to Their Own Devices
Oct 30, 2025
Asher Davila, Principal Security Researcher at Palo Alto Networks, dives deep into the alarming findings from the 2025 Device Security Enterprise Threat Report. Over 21% of connected devices have known vulnerabilities, with 32.5% unmanaged, creating serious security blind spots. He discusses common oversight with personal devices and the challenges posed by credential-based attacks. Asher emphasizes the importance of effective asset lifecycle governance and why zero trust approaches are hindered by management gaps. Proactive defenses are crucial for breaking the attack chain.
AI Snips
Chapters
Transcript
Episode notes
Unplanned Path Into IoT Research
- Asher stumbled into IoT security via a reverse-engineering challenge that turned out to be an interview task.
- He joined a startup (Simbox) focused on IoT which was later acquired by Palo Alto Networks.
Accept And Monitor Unfixable Devices
- Accept risk when you cannot replace or fix legacy devices but ensure you know they exist.
- Monitor those devices constantly for attacks, compromises, or malware infection.
Device Diversity Creates Visibility Gaps
- Large organizations average ~80 device types, creating complex inventory and visibility challenges.
- Diversity of OSes, versions, and BYOD multiplies blind spots for administrators.
