
The Upcoming Security Webinar Healthcare Can't Miss | Interview with Clay Maddux

Paused
The Upcoming Security Webinar Healthcare Can't Miss | Interview with Clay MadduxThe 229 Podcast
Questions Answered in This Episode
- Why are adversary-in-the-middle attacks targeting healthcare SaaS applications more than ever?
- How are attackers stealing employee paychecks through Workday and similar platforms?
- What's changed in phishing tactics compared to attacks from two or three years ago?
- Why can't most organizations detect session theft and browser-based attacks today?
- How do you connect browser alerts, identity risks, and phishing signals into one picture?
About This Episode
July 22, 2026: Clay Maddux, Healthcare Horizon Practice Director at CrowdStrike, joins Drex DeFord to preview a free, live webinar on August 13th that tackles one of the fastest-growing threats in healthcare security: adversary-in-the-middle attacks on SaaS applications. Clay shares a preview of what's coming, including real cases of "payroll pirates" hijacking Workday accounts and rerouting employee paychecks, plus a live demo of browser-in-browser phishing in action. Open to the entire healthcare security community, no CrowdStrike account required. Register now and bring your team.
Register for the Defending Against AiTM Attacks in Healthcare Webinar: https://go.crowdstrike.com/2026-08-aitm-healthcare.html?utm_campaign=stop_ai_accelerated_adversaries&utm_medium=evt&utm_source=prtn&utm_language=en-us
Key Points:
01:10 Webinar Invitation
02:37 What Attendees Learn
04:31 Phishing And Browser Attacks
05:07 Live Demo And Token Theft
Keep up to date on the latest in health IT:
https://thisweekhealth.com/news/
Donate: Alex’s Lemonade Stand: Foundation for Childhood Cancer
Transcript
This transcription is provided by artificial intelligence. We believe in technology but understand that even the smartest robots can sometimes get speech recognition wrong. The Upcoming Security Webinar Healthcare Can't Miss| Executive Interview with Clay Maddux [00:00:00] Drex DeFord: Hey, everyone, I'm Drex, and I invited Clay Maddox, the h- healthcare horizon practice director, to join me today to talk about what I think is gonna be a really cool online education session that the team at CrowdStrike's doing on August 13th at 1:00 Eastern, and I'll put a link, uh, in the comments so that you can register and sort of check this out. Hi, Clay. I'm glad you're here. Clay Maddux: Hey, Drex. Good to see you. Drex DeFord: Uh, so tell me a little bit about the event and the topic. It's about the surge that you guys are seeing in the adversary in the middle attacks that are kind of happening across the board, but definitely in healthcare too. Clay Maddux: Yeah. Um, you know, as you know, and I'm sure most of your view- of your viewers know, CrowdStrike has a really large incident response and threat intelligence practice, and we've seen a material increase in adversary in the middle or man in the middle types of attacks that are starting to get really focused on SaaS applications particularly in [00:01:00] healthcare, but across all verticals as well. And so we thought it'd be a good idea to bring some of that information, you know, to our healthcare teams and let them know what they need to be on the lookout for, how CrowdStrike helps, but also a lot of good general good best practices around what adversaries are doing as they constantly evolve their tradecraft. Drex DeFord: I mean, when it shows up in the incident response- in, e- engagements that you're doing, 'cause I know you do a lot of those. Mm-hmm. Um for me, that feels like it's a really big deal, so that's when we were chatting, I was like, "I'm gonna hit record 'cause I, I kinda wanna get this." For folks who are going to be attending the, the, the educational event, the webinar, they're gonna leave with some pretty solid practical insights, right? Clay Maddux: Yeah. Yeah, absolutely., Um, You know, recently, like I'd mentioned, we've seen a, a really large increase in adversaries targeting SaaS applications. Drex DeFord: Mm. Clay Maddux: In particular, we've seen some stories where, and, and this is happening to [00:02:00] healthcare systems, to hospitals here in the country, what we're kind of, you know, dubbing as payroll pirates, where attackers are using various types of tradecraft that we're gonna talk about on this webinar as adversary in the middle types of attacks, and they're pivoting directly into Workday, for example. They're changing payment information of employees- Mm ... and they're stealing paychecks, and no one really knows until that employee, you know, says, "Hey, why didn't I get paid?" And we start doing a forensic investigation., It, it stinks that these things are happening and people are being impacted in that manner. Yeah ... but it's, you know, happening, um, more often and, and, over the entire, you know, landscape where we feel like it's important for everybody to understand what's happening out there and be on the lookout for it. Drex DeFord: So who, who's going to do the webinar? I know you have a bunch of, like, super smart people CrowdStrike. Who's gonna be actually running the, education session? Clay Maddux: Great question. This is a jam-packed webinar, we're going to have our practice leads who [00:03:00] focus on healthcare from threat intelligence, identity protection, as well as browser protection and visibility, all involved in this, webinar. Um, we're going to, uh, or r- what people walk away with is we're going to walk through a really deep dive of the threat landscape that I'm discussing. So, you know, why are we talking about this? Mm. How are adversaries changing their tradecraft? We're gonna really dial into phishing. You know, what was happening, say, two, three years ago is a lot different to the type of attacks that are happening now, and really walk through all of those different flavors of attacks and how people are getting in. One of those things are browser and browser attacks, where there's session theft, and that's happening in a browser, and most organizations don't have visibility into that or can't correlate those alerts back to their identity alerts and identity risk. So we wanna combine, uh areas of expertise in those dimensions and bring them all together.[00:04:00] And then we're also going to walk through a live demo of what phishing looks like- in a browser. So when a phishing attempt happens and a user makes that click, and then they get redirected to a website that's owned by an adversary, what does that browser in browser example look like? And we'll be able to demonstrate to the audience, the difference between things like encrypted versus unencrypted tokens, what a harvested token looks like, et cetera, and why all of these things help paint a bigger picture than, say, just a, a low-level alert about a potentially risky login or a low-level alert about a potential, phishing email. You need to be able to connect all of these different things together, particularly with browser usage, and that's what we're gonna be able to show on top of the threat intelligence and landscape information. Drex DeFord: Yeah, makes sense. Super cool. August 13th, 1:00 PM Eastern. Anyone can join? Do you have to be a CrowdStrike- [00:05:00] Yeah customer? Clay Maddux: No, no. We wanna put this information out there to, um, the entire healthcare security community, so you don't have to be a CrowdStrike customer to join. Um, so we'd love to have everybody and anybody who's interested in this information. Drex DeFord: thanks for your time today. I really appreciate it. Yeah. Can't wait to see you and CrowdStrike healthcare team online August 13th, 1:00 PM, for the Adversary in the Middle webinar. It sounds like there's a whole bunch of other stuff in there, too. Yeah. Really exciting to, uh, to see, and I'll put the registration link in the comments section in this post, in this podcast below. Clay Maddux: Absolutely. Thank you, Drex




