Research Saturday cover art

All Episodes

Research Saturday — 463 episodes

#
Title
1

Who let the AI hack?

2

A RAT in the spreadsheet.

3

The botnet that scouts before it strikes.

4

A little help from your search engine.

5

The driver's seat to ransomware.

6

Cold lures, hot targets.

7

When trusted sites turn.

8

Conti-versal opinions.

9

Is your enterprise AI strategy delivering ROI yet? [AI Security Brief]

10

More bark than byte.

11

Peeling back Banana RAT.

12

This Sparrow doesn't migrate.

13

You've been muted...permanently.

14

The skills pay the bills.

15

Ghosted by Grafana

16

Scam papers served.

17

The spy who logged me in.

18

Double-edged threat.

19

A QRazy clever scam.

20

A new breed of RAT.

21

A wolf in admin clothing.

22

Startup surge sparks spy interest.

23

When “safe” documents aren’t.

24

A subtle flaw, a massive blast radius.

25

Your AI sidekick might be a spy.

26

The scareware rabbit hole.

27

The parking lot of digital danger.

28

Telegram for the throne.

29

Stealer in the status bar.

30

The phishing kit that thinks like a human.

31

The link knows all.

32

Caught in the funnel.

33

Picture perfect deception.

34

Walking on EggStremes.

35

Don’t trust that app!

36

Excel-lerating cyberattacks.

37

The lies that let AI run amok.

38

Root access to the great firewall.

39

When macOS gets frostbite.

40

A new stealer hiding behind AI hype.

41

Two RMMs walk into a phish…

42

When clicks turn criminal.

43

A fine pearl gone rusty.

44

Attack of the automated ops.

45

A look behind the lens.

46

Smile for the malware.

47

No honor among thieves.

48

China’s stealthiest spy operation yet.

49

Inside Curly COMrades.

50

Browser attacks without downloads.

51

Data leak without a click.

52

Don’t trust that app!

53

Cracks in the wall.

54

Beyond the smoke screen.

55

The CVE countdown clock.

56

When malware plays pretend.

57

nOAuth-ing to see here.

58

Muddled Libra: From Spraying to Preying in 2025 [Threat Vector]

59

Creeping like a spider.

60

Click here to steal.

61

Botnet’s back, tell a friend.

62

A tale of two botnets.

63

Signed, sealed, exploitable.

64

Hiding in plain sight with vibe coding.

65

A new stealer hiding behind AI hype.

66

Triofox and the key to disaster.

67

Pandas with a purpose.

68

Leveling up their credential phishing tactics.

69

Hijacking wallets with malicious patches.

70

When AI gets a to-do list.

71

China’s new cyber arsenal revealed.

72

Crafting malware with modern metals.

73

The new malware on the block.

74

Bybit’s $1.4B breach.

75

Breaking barriers, one byte at a time.

76

Excel-lerating cyberattacks.

77

The ransomware clones of HellCat & Morpheus.

78

Botnet’s back, tell a friend.

79

Caught in the contagious interview.

80

From small-time scams to billion-dollar threats.

81

Bot or not? The fake CAPTCHA trick spreading Lumma malware.

82

Cleo’s trojan horse.

83

A Digital Eye on supply-chain-based espionage attacks.

84

LightSpy's dark evolution.

85

A cute cover for a dangerous vulnerability.

86

The hidden cost of data hoarding.

87

Crypto client or cyber trap?

88

On the prowl for mobile malware.

89

Quishing for trouble.

90

Watching the watchers. IoT vulnerabilities exposed by AI.

91

The JPHP loader breaking away from the pack.

92

Leaking your AWS API keys, on purpose?

93

Exposing AI's Achilles heel.

94

Credential harvesters in the cloud.

95

A firewall wake up call.

96

Velvet Ant's silent invasion.

97

LLM security 101.

98

New targets, new tools, same threat.

99

Ransomware on repeat.

100

Podcast bait, malware switch.

101

Beyond the permissions wall.

102

Hook, line, and sinker.

103

Spamageddon: Xeon Sender’s cloudy SMS attack revealed!

104

The playbook for outpacing China.

105

Pop goes the developer.

106

MaaS infrastructure exposed.

107

Essential tools with critical security challenges.

108

Prompts gone rogue.

109

Spinning the web of tangled tactics.

110

The Black Basta ransomware riddle.

111

Olympic scammers go for gold.

112

On the prowl for mobile malware.

113

Encore: Welcome to New York, it's been waitin' for you.

114

APT36's cyber blitz on India.

115

Piercing the through the fog.

116

Exploring the mechanics of Infostealer malware.

117

Riding the hype for new Arc browser.

118

1700 IPs and counting.

119

International effort dismantles LockBit.

120

From secret images to encryption keys.

121

The double-edged sword of cyber espionage.

122

Geopolitical tensions rise with China.

123

Cerber ransomware strikes Linux.

124

The art of information gathering.

125

Breaking down a high-severity vulnerability in Kubernetes.

126

Leaking your AWS API keys, on purpose?

127

The supply chain in disarray.

128

HijackLoader unleashed: Evolving threats and sneaky tactics.

129

Inside SendGrid's phishy business.

130

Understanding the multi-tiered impact of ransomware.

131

The return of a malware menace.

132

Web host havoc: Unveiling the Manic Menagerie campaign.

133

Hackers come hopping back.

134

Ransomware is coming.

135

Weathering the internet storm.

136

Hooked on pirated macOS applications.

137

A firewall wake up call.

138

Dual Russian cyber gangs hit 23 companies.

139

Diving deep into Phobos ransomware.

140

Encore: What malicious campaign is lurking under the surface?

141

Encore: Compromised military tech?

142

Shedding light on fighting Ursa.

143

On the hunt for popping up kernel drives.

144

Exploits and vulnerabilities.

145

Encore: Another infection with new malware.

146

The malicious YoroTrooper in disguise.

147

Encore: Old malware returns in a new way.

148

Sandman doesn't slow malware down.

149

No rest for the wicked HiatusRAT.

150

AMBERSQUID hides in the depths.

151

Unwanted guests harvest your information.

152

Targets from DuckTail.

153

Downloading cracked software.

154

Behind the Google shopping ad masks.

155

A look into the emotions and anxieties of the highest levels of decision-making.

156

No honor in being a criminal.

157

Thwarting Muddled Libra.

158

Google's not being ghosted from vulnerabilities.

159

Politicians targeted by RomCom.

160

It's raining credentials.

161

Who is that stealing my credentials?

162

Phishing for leeches.

163

Welcome to New York, it's been waitin' for you.

164

SCARLETEEL zaps back again.

165

Creating PANDA-monium.

166

The power behind artificial intelligence.

167

Unleashing the crypto gold rush.

168

Managing machine learning risks.

169

A new botnet takes a frosty bite out of the gaming industry.

170

Lancefly screams bloody Merdoor.

171

8 GoAnywhere MFT breaches and counting.

172

Dangerous vulnerabilities in H.264 decoders.

173

Running away from operation Tainted Love.

174

Phishing campaign takes the energy out of Chinese nuclear industry.

175

HinataBot focuses on DDoS attack.

176

Don't let the Elon Musk crypto giveaway scam swindle you.

177

New Dero cryptojacking operation concentrates on locating Kubernetes.

178

A dark side to LLMs.

179

Blackfly flies back again.

180

Popunders are not the good kind of ads.

181

ChatGPT grants malicious wishes?

182

Files stolen from a sneaky SymStealer.

183

New exploits are tricking Chrome.

184

The next hot AI scam.

185

Implementing and achieving security resilience.

186

Knocking down the legs of the industrial security triad.

187

Can ransomware turn machines against us?

188

Flagging firmware vulnerabilities.

189

Billbug infests government agencies.

190

DUCKTAIL waddles back again.

191

Stealer malware from Russia.

192

Encore: LemonDucks evading detection.

193

Encore: Vulnerabilities in IoT devices.

194

Hijacking holiday spirit with phishing scams.

195

Cybersecurity during the World Cup.

196

Old malware returns in a new way.

197

Encore: The secrets behind Docker.

198

Another infection with new malware.

199

An in-depth look on the Crytox ransomware family.

200

Over-the-air 0-day vulnerabilities.

201

Bugs and working from home.

202

New tools target governments in Middle East?

203

Noberus ransomware: evolving tactics.

204

Google Drive used for malware?

205

Targeting your browser bookmarks?

206

Keeping an eye on RDS vulnerabilities.

207

An increase in bypassing bot management?

208

Evilnum APT returns with new targets.

209

LockBit's contradiction on encryption speed.

210

How a wide scale Facebook campaign stole 1 million credentials.

211

Clipminer: Making millions off of malware.

212

Fake job ads and how to spot them.

213

Iran-linked Lyceum Group adds a new weapon to its arsenal.

214

What malicious campaign is lurking under the surface?

215

Has GOLD SOUTHFIELD resumed operations?

216

A record breaking DDoS attack.

217

Information operations during a war.

218

Could REvil have a copycat?

219

Lazarus Targets Chemical Sector With 'Dream Job.'

220

Dissecting the Spring4Shell vulnerability.

221

New developments in the WSL attack.

222

LemonDucks evading detection.

223

Compromised military tech?

224

AutoWarp bug leads to Automation headaches.

225

Vulnerabilities in IoT devices.

226

Vulnerabilities bring in the hackers.

227

Attackers coming in from the Backdoor?

228

BABYSHARK is swimming again!

229

A fight to defend Taiwan financial institutions.

230

The secrets behind Docker.

231

A popular malware scheme and pay-per-install services.

232

The breakdown of Shuckworm's continued cyber attacks against Ukraine.

233

Implications of data leaks of sensitive OT information.

234

The story of REvil: From origin to beyond.

235

An abuse of trust: Potential security issues with open redirects.

236

Noberus ransomware: Coded in Rust and tailored to victim.

237

Instagram hijacks all start with a phish.

238

SysJoker backdoor masquerades as benign updates.

239

The persistent and patient nature of advanced threat actors.

240

Use of legitimate tools possibly linked to Seedworm.

241

A collaboration stumbles upon threat actor Lyceum.

242

Keeping APIs on the radar: Evaluating the banking industry.

243

The rise of Karakurt Hacking Team.

244

Encore: When big ransomware goes away, where should affiliates go?

245

CyberWire Pro Research Briefing from 12/21/2021.

246

Discovering ChaosDB, a critical vulnerability in the CosmosDB.

247

FIN7 repositioning focus into ransomware.

248

Getting in and getting out with SnapMC.

249

CyberWire Pro Research Briefing from 11/23/2021

250

Using bidirectionality override characters to obscure code.

251

A glimpse into TeamTNT.

252

An incident response reveals itself as GhostShell tool, ShellClient.

253

Malware sometimes changes its behavior.

254

When big ransomware goes away, where should affiliates go?

255

Groove Gang making a name for themselves.

256

Taking a closer look at UNC1151.

257

IoT security and the need for randomness.

258

Vulnerabilities in the public cloud.

259

An IoT educational exercise reveals a far-reaching vulnerability.

260

A Google Chrome update that just didn't feel right.

261

Like a computer network but for physical objects.

262

Joker malware family: not a joke for Google Play.

263

Exploring vulnerabilities of off-the-shelf software.

264

You can add new features, just secure the old stuff first.

265

SideCopy malware campaigns expand and evolve.

266

China's influence grows through Digital Silk Road Initiative.

267

Free malware with cracked software.

268

Enabling connectivity enables exposures.

269

Dealing illicit goods on encrypted chat apps.

270

Malware in pirated Windows installation files.

271

Exhibiting advanced APT-like behavior.

272

Primitive Bear spearphishes for Ukrainian entities.

273

Taking a look behind the Science of Security.

274

Bad building blocks: a new and unusual phishing campaign.

275

EtterSilent: a popular, versatile maldoc builder.

276

Leveraging COVID-19 themes for malicious purposes.

277

Jack Voltaic: critical infrastructure resiliency project, not a person.

278

SUPERNOVA activity and its possible connection to SPIRAL threat group.

279

A snapshot of the ransomware threat landscape.

280

Bulletproof hosting (BPH) and how it powers cybercrime.

281

Social engineering: MINEBRIDGE RAT embedded to look like job résumés.

282

Strategic titles point to something more than a commodity campaign.

283

Ezuri: Regenerating a different kind of target.

284

How are we doing in the industrial sector?

285

BendyBear: difficult to detect and downloader of malicious payloads.

286

Keeping data confidential with fully homomorphic encryption.

287

Diving deep into North Korea's APT37 tool kit.

288

Shining a light on China's cyber underground.

289

Attackers (ab)using Google Chrome.

290

Using the human body as a wire-like communication channel.

291

"Follow the money" the cybersecurity way.

292

The Kimsuky group from North Korea expands spyware, malware and infrastructure.

293

Trickbot may be down, but can we count it out?

294

Manufacturing sector is increasingly a target for adversaries.

295

Emotet reemerges and becomes one of most prolific threat groups out there.

296

Encore: Unpacking the Malvertising Ecosystem. [Research Saturday]

297

Encore: Seedworm digs Middle East intelligence. [Research Saturday]

298

Advertising Software Development Kit (SDK): serving up more than just in-app ads and logging sensitive data.

299

Following DOJ indictment, a look back on NotPetya and Olympic Destroyer research.

300

SSL-based threats remain prevalent and are becoming increasingly sophisticated.

301

Encore: Using global events as lures for malicious activity.

302

Misconfigured identity and access management (IAM) is much more widespread.

303

That first CVE was a fun find, for sure.

304

PoetRAT: a complete lack of operational security.

305

Leveraging for a bigger objective.

306

The Malware Mash!

307

Just saying there are attacks is not enough.

308

Intentionally not drawing attention.

309

It's still possible to find ways to break out.

310

Smaug: Ransomware-as-a-service drag(s)on.

311

What came first, the Golden Chickens or more_eggs?

312

Election 2020: What to expect when we are electing.

313

Leveraging legitimate tools.

314

Going after the most valuable data.

315

They fooled a lot of people.

316

Using global events as lures.

317

Waiting for their victims.

318

Like anything these days, you have to disinfect it first.

319

Detecting Twitter bots in real time.

320

It was only a matter of time.

321

Every time we get smarter, the bad guy changes something.

322

Are you running what you think you're running?

323

Enter the RAT.

324

Click here to update your webhook.

325

The value of the why and the who.

326

Due diligence cannot be done as a one-off.

327

Twofold snooping venture.

328

Naming and shaming is the worst thing we can do.

329

Gangnam Industrial Style APT campaign targets South Korea.

330

The U.S. campaign trail is actually quite secure.

331

Fingerprint authentication is not completely secure.

332

Contact tracing as COVID-19 aid.

333

How low can they go? A spike in Coronavirus phishing.

334

Profiling an audacious Nigerian cybercriminal.

335

A rough year ahead for ransomware attacks - and how to stop them.

336

Hidden dangers inside Windows and LINUX computers.

337

The security implications of cloud infrastructure in IoT.

338

TLS is here to stay.

339

Overworked developers write vulnerable software.

340

Application tracking in Wacom tablets.

341

New vulnerabilities in PC sound cards.

342

If you can't detect it, you can't steal it.

343

The Chameleon attacks Online Social Networks.

344

Tracking one of China's hidden hacking groups.

345

Know Thine Enemy - Identifying North American Cyber Threats.

346

Clever breaches demonstrate IoT security gaps.

347

Profiling the Linken Sphere anti-detection browser.

348

A Jira vulnerability that’s leaking data in the public cloud.

349

Inside Magecart and Genesis.

350

WAV files carry malicious data payloads.

351

Targeting routers to hit gaming servers.

352

Mustang Panda leverages Windows shortcut files.

353

Sodinokibi aka REvil connections to GandCrab.

354

Monitoring the growing sophistication of PKPLUG.

355

Usable security is a delicate balance.

356

Masad Steals via Social Media.

357

Hoping for SOHO security.

358

Decrypting ransomware for good.

359

The fuzzy boundaries of APT41.

360

Focusing on Autumn Aperture.

361

Leaky guest networks and covert channels.

362

Bluetooth blues: KNOB attack explained.

363

VOIP phone system harbors decade-old vulnerability.

364

Emotet's updated business model.

365

Gift card bots evolve and adapt.

366

Detecting dating profile fraud.

367

Unpacking the Malvertising Ecosystem.

368

Package manager repository malware detection.

369

Day to day app fraud in the Google Play store.

370

Nansh0u not your normal cryptominer.

371

Opportunistic botnets round up vulnerable routers.

372

Giving everyone a stake in the success of Open Source implementation.

373

Middleboxes may be meddling with TLS connections.

374

Apps on third-party Android store carry unwelcome code.

375

Xwo scans for default credentials and exposed web services.

376

Blockchain bandits plunder weak wallets.

377

A fresh look at GOSSIPGIRL and the Supra Threat Actors.

378

Elfin APT group targets Middle East energy sector.

379

Steganography enables sophisticated OceanLotus payloads.

380

Sea Turtle state-sponsored DNS hijacking.

381

Deep Learning threatens 3D medical imaging integrity.

382

Undetectable vote manipulation in SwissPost e-voting system.

383

Establishing software root of trust unconditionally.

384

Lessons learned from Ukraine elections.

385

Alarming vulnerabilities in automotive security systems.

386

Ryuk ransomware relationship revelations.

387

ThinkPHP exploit from Asia-Pacific region goes global.

388

Job-seeker exposes banking network to Lazurus Group.

389

Fake Fortnite app scams infect gamers.

390

Rosneft suspicions shift from espionage to business email compromise.

391

Seedworm digs Middle East intelligence.

392

Trends and tips for cloud security.

393

Online underground markets in the Middle East.

394

Amplification bots and how to detect them.

395

Luring IoT botnets to the honeypot.

396

Magecart payment card theft analysis.

397

NOKKI, Reaper and DOGCALL target Russians and Cambodians.

398

Apple Device Enrollment Program vulnerabilities explored.

399

The Sony hack and the perils of attribution.

400

Operation Red Signature targets South Korean supply chain.

401

Getting an education on Cobalt Dickens.

402

Doubling down on Cobalt Group activity.

403

Establishing international norms in cyberspace.

404

Election protection.

405

Faxploitation.

406

Stormy weather in the Office 365 cloud.

407

Driving GPS manipulation.

408

Cryptojacking criminal capers continue.

409

Sophisticated FIN7 criminal group hits payment card data.

410

ICS honeypots attract sophisticated snoops.

411

Android device eavesdropping investigation.

412

Leafminer espionage digs the Middle East.

413

ATM hacks on the rise.

414

Cyber espionage coming from Chinese University.

415

Stealthy ad fraud campaign evades detection.

416

Thrip espionage group lives off the land.

417

Cortana voice assistant lets you in.

418

BabaYaga strangely symbiotic Wordpress malware.

419

Measuring the spearphishing threat.

420

A new approach to mission critical systems.

421

No Distribute Scanners help sell malware.

422

VPNFilter malware could brick devices worldwide.

423

LG smartphone keyboard vulnerabilities.

424

Cyber bank heists.

425

Winnti Umbrella Chinese threat group.

426

Islamic State propaganda persistence.

427

UPnProxy infiltrates home routers.

428

Threat actors hijack Lojack.

429

Three pillars of Artificial Intelligence.

430

BlackTDS and ThreadKit offered in criminal markets.

431

New MacOS backdoor linked to OceanLotus.

432

InnaputRAT exfiltrates victim data.

433

Energetic Dragonfly and DYMALLOY Bear 2.0.

434

Crypto crumple zones.

435

Chasing FlawedAMMYY.

436

Code comments cause SAML conundrum.

437

Cryptojacking injections heat up.

438

Dark Caracal APT steals out of Lebanon.

439

Lebal malware phishes for victims.

440

Phishing for holiday winnings.

441

The uncanny HEX men.

442

IcedID banking trojan.

443

Advanced adware with nation-state tactics.

444

Targeting Olympic organizations.

445

Fancy Bear Duping Doping Domains.

446

Shake Your MoneyTaker.

447

TRISIS Malware: Fail-safe fail.

448

Hunting the Sowbug.

449

Keyboys back in town.

450

The unique culture of the Middle Eastern and North African underground.

451

Stealthy Zberp Banking Trojan.

452

Staying ahead of Fast Flux Networks.

453

Waiting for Terdot, a sneaky banking Trojan.

454

Dark Net Pricing with Flashpoint's Liv Rowley.

455

Taiwan Bank Heist and Lazurus Group with BAE's Adrian Nish.

456

Exploring Phishing Kits with Duo Security's Jordan Wright.

457

Tracking a Trojan: KHRAT.

458

WireX BotNet with Justin Paine from Cloudflare.

459

Synthesized DNA Malware with Peter Ney.

460

Android Toast Overlay: Ryan Olson from Palo Alto Networks.

461

APT 33: FireEye's John Hultquist on an Iranian Cyber Espionage Group.

462

Pacifier APT : Bitdefender's Liviu Arsene describes a sophisticated, multifaceted malware campaign.

463

Cobian RAT: Zscaler’s Deepen Desai describes some clever malware.