Blog
They don’t break in anymore. They log in.
One of the most dangerous things on the internet right now is not sophisticated malware – it is a stolen username and password. Principal Threat Intelligence Analyst David Kasabji explains why the perimeter is now identity, and what it takes to stay ahead.
Ask most people what keeps a threat intelligence analyst awake at night, and they will picture some sophisticated, never-before-seen piece of malware. The reality is far more mundane, and far more dangerous.
The most dangerous thing on the internet right now is a username and a password – stolen from someone’s personal laptop, sold for three euros on a criminal marketplace, and used months later to walk straight into a corporate network. No exploit. No zero-day. No alarm going off. Just a login. That, says David Kasabji, Principal Threat Intelligence Analyst at Conscia, is the reality we operate in every day.
How malware changed the threat landscape
Two changes have reshaped the threat environment. First, the line between nation-state actors and cybercriminals has largely dissolved – state-sponsored groups now run financially motivated operations alongside espionage, using the same infrastructure, tools and access brokers. Second, infostealers have exploded into what David openly calls a pandemic: millions of credentials harvested every month, indexed and sold, feeding an entire ecosystem of access brokers who resell entry into corporate environments to ransomware groups.
They don’t break in anymore. They log in. The perimeter is no longer your firewall. The perimeter is identity.
David Kasabji
Head of Threat Intelligence
Why threat intelligence is essential for detecting identity-based attacks
This creates a genuinely difficult detection problem, because the attack looks like normal behaviour: a valid user, valid credentials, a plausible time of day, a known application. The only way to catch it is context – and context requires intelligence.
But cybersecurity is drowning in data. The challenge is not access to threat feeds; it is knowing which data actually matters for your organisation, your industry, your exposure. Get it wrong in either direction, and it is costly: too much noise and your analysts burn out chasing false positives; too little signal and a real intrusion sits undetected for weeks.
Continuous threat intelligence: closing the gap before attackers move
The only scalable answer is threat intelligence tailored to your business – intelligence that tells you which threats are targeting you, what techniques, tactics and procedures they use, how exposed your supply chain partners are, and whether your credentials are already circulating on the dark web.
And it must be continuous, because intrusions do not happen on a quarterly reporting cycle. An infostealer infection from a month ago can become a ransomware intrusion today. Continuous monitoring closes that window – exposing the threat earlier than the attacker can activate it.
That is exactly what we build at Conscia. Our cyber threat intelligence cuts through the noise, surfaces the real threats focused on our clients, and feeds directly into our detection and response systems. Because intelligence that does not drive action is just information — and information alone cannot stop cyber threats.
Watch the video to hear David explain how the attacker playbook has changed — and what modern defence really requires.
Related