All Episodes
Research Saturday — 463 episodes
Who let the AI hack?
A RAT in the spreadsheet.
The botnet that scouts before it strikes.
A little help from your search engine.
The driver's seat to ransomware.
Cold lures, hot targets.
When trusted sites turn.
Conti-versal opinions.
Is your enterprise AI strategy delivering ROI yet? [AI Security Brief]
More bark than byte.
Peeling back Banana RAT.
This Sparrow doesn't migrate.
You've been muted...permanently.
The skills pay the bills.
Ghosted by Grafana
Scam papers served.
The spy who logged me in.
Double-edged threat.
A QRazy clever scam.
A new breed of RAT.
A wolf in admin clothing.
Startup surge sparks spy interest.
When “safe” documents aren’t.
A subtle flaw, a massive blast radius.
Your AI sidekick might be a spy.
The scareware rabbit hole.
The parking lot of digital danger.
Telegram for the throne.
Stealer in the status bar.
The phishing kit that thinks like a human.
The link knows all.
Caught in the funnel.
Picture perfect deception.
Walking on EggStremes.
Don’t trust that app!
Excel-lerating cyberattacks.
The lies that let AI run amok.
Root access to the great firewall.
When macOS gets frostbite.
A new stealer hiding behind AI hype.
Two RMMs walk into a phish…
When clicks turn criminal.
A fine pearl gone rusty.
Attack of the automated ops.
A look behind the lens.
Smile for the malware.
No honor among thieves.
China’s stealthiest spy operation yet.
Inside Curly COMrades.
Browser attacks without downloads.
Data leak without a click.
Don’t trust that app!
Cracks in the wall.
Beyond the smoke screen.
The CVE countdown clock.
When malware plays pretend.
nOAuth-ing to see here.
Muddled Libra: From Spraying to Preying in 2025 [Threat Vector]
Creeping like a spider.
Click here to steal.
Botnet’s back, tell a friend.
A tale of two botnets.
Signed, sealed, exploitable.
Hiding in plain sight with vibe coding.
A new stealer hiding behind AI hype.
Triofox and the key to disaster.
Pandas with a purpose.
Leveling up their credential phishing tactics.
Hijacking wallets with malicious patches.
When AI gets a to-do list.
China’s new cyber arsenal revealed.
Crafting malware with modern metals.
The new malware on the block.
Bybit’s $1.4B breach.
Breaking barriers, one byte at a time.
Excel-lerating cyberattacks.
The ransomware clones of HellCat & Morpheus.
Botnet’s back, tell a friend.
Caught in the contagious interview.
From small-time scams to billion-dollar threats.
Bot or not? The fake CAPTCHA trick spreading Lumma malware.
Cleo’s trojan horse.
A Digital Eye on supply-chain-based espionage attacks.
LightSpy's dark evolution.
A cute cover for a dangerous vulnerability.
The hidden cost of data hoarding.
Crypto client or cyber trap?
On the prowl for mobile malware.
Quishing for trouble.
Watching the watchers. IoT vulnerabilities exposed by AI.
The JPHP loader breaking away from the pack.
Leaking your AWS API keys, on purpose?
Exposing AI's Achilles heel.
Credential harvesters in the cloud.
A firewall wake up call.
Velvet Ant's silent invasion.
LLM security 101.
New targets, new tools, same threat.
Ransomware on repeat.
Podcast bait, malware switch.
Beyond the permissions wall.
Hook, line, and sinker.
Spamageddon: Xeon Sender’s cloudy SMS attack revealed!
The playbook for outpacing China.
Pop goes the developer.
MaaS infrastructure exposed.
Essential tools with critical security challenges.
Prompts gone rogue.
Spinning the web of tangled tactics.
The Black Basta ransomware riddle.
Olympic scammers go for gold.
On the prowl for mobile malware.
Encore: Welcome to New York, it's been waitin' for you.
APT36's cyber blitz on India.
Piercing the through the fog.
Exploring the mechanics of Infostealer malware.
Riding the hype for new Arc browser.
1700 IPs and counting.
International effort dismantles LockBit.
From secret images to encryption keys.
The double-edged sword of cyber espionage.
Geopolitical tensions rise with China.
Cerber ransomware strikes Linux.
The art of information gathering.
Breaking down a high-severity vulnerability in Kubernetes.
Leaking your AWS API keys, on purpose?
The supply chain in disarray.
HijackLoader unleashed: Evolving threats and sneaky tactics.
Inside SendGrid's phishy business.
Understanding the multi-tiered impact of ransomware.
The return of a malware menace.
Web host havoc: Unveiling the Manic Menagerie campaign.
Hackers come hopping back.
Ransomware is coming.
Weathering the internet storm.
Hooked on pirated macOS applications.
A firewall wake up call.
Dual Russian cyber gangs hit 23 companies.
Diving deep into Phobos ransomware.
Encore: What malicious campaign is lurking under the surface?
Encore: Compromised military tech?
Shedding light on fighting Ursa.
On the hunt for popping up kernel drives.
Exploits and vulnerabilities.
Encore: Another infection with new malware.
The malicious YoroTrooper in disguise.
Encore: Old malware returns in a new way.
Sandman doesn't slow malware down.
No rest for the wicked HiatusRAT.
AMBERSQUID hides in the depths.
Unwanted guests harvest your information.
Targets from DuckTail.
Downloading cracked software.
Behind the Google shopping ad masks.
A look into the emotions and anxieties of the highest levels of decision-making.
No honor in being a criminal.
Thwarting Muddled Libra.
Google's not being ghosted from vulnerabilities.
Politicians targeted by RomCom.
It's raining credentials.
Who is that stealing my credentials?
Phishing for leeches.
Welcome to New York, it's been waitin' for you.
SCARLETEEL zaps back again.
Creating PANDA-monium.
The power behind artificial intelligence.
Unleashing the crypto gold rush.
Managing machine learning risks.
A new botnet takes a frosty bite out of the gaming industry.
Lancefly screams bloody Merdoor.
8 GoAnywhere MFT breaches and counting.
Dangerous vulnerabilities in H.264 decoders.
Running away from operation Tainted Love.
Phishing campaign takes the energy out of Chinese nuclear industry.
HinataBot focuses on DDoS attack.
Don't let the Elon Musk crypto giveaway scam swindle you.
New Dero cryptojacking operation concentrates on locating Kubernetes.
A dark side to LLMs.
Blackfly flies back again.
Popunders are not the good kind of ads.
ChatGPT grants malicious wishes?
Files stolen from a sneaky SymStealer.
New exploits are tricking Chrome.
The next hot AI scam.
Implementing and achieving security resilience.
Knocking down the legs of the industrial security triad.
Can ransomware turn machines against us?
Flagging firmware vulnerabilities.
Billbug infests government agencies.
DUCKTAIL waddles back again.
Stealer malware from Russia.
Encore: LemonDucks evading detection.
Encore: Vulnerabilities in IoT devices.
Hijacking holiday spirit with phishing scams.
Cybersecurity during the World Cup.
Old malware returns in a new way.
Encore: The secrets behind Docker.
Another infection with new malware.
An in-depth look on the Crytox ransomware family.
Over-the-air 0-day vulnerabilities.
Bugs and working from home.
New tools target governments in Middle East?
Noberus ransomware: evolving tactics.
Google Drive used for malware?
Targeting your browser bookmarks?
Keeping an eye on RDS vulnerabilities.
An increase in bypassing bot management?
Evilnum APT returns with new targets.
LockBit's contradiction on encryption speed.
How a wide scale Facebook campaign stole 1 million credentials.
Clipminer: Making millions off of malware.
Fake job ads and how to spot them.
Iran-linked Lyceum Group adds a new weapon to its arsenal.
What malicious campaign is lurking under the surface?
Has GOLD SOUTHFIELD resumed operations?
A record breaking DDoS attack.
Information operations during a war.
Could REvil have a copycat?
Lazarus Targets Chemical Sector With 'Dream Job.'
Dissecting the Spring4Shell vulnerability.
New developments in the WSL attack.
LemonDucks evading detection.
Compromised military tech?
AutoWarp bug leads to Automation headaches.
Vulnerabilities in IoT devices.
Vulnerabilities bring in the hackers.
Attackers coming in from the Backdoor?
BABYSHARK is swimming again!
A fight to defend Taiwan financial institutions.
The secrets behind Docker.
A popular malware scheme and pay-per-install services.
The breakdown of Shuckworm's continued cyber attacks against Ukraine.
Implications of data leaks of sensitive OT information.
The story of REvil: From origin to beyond.
An abuse of trust: Potential security issues with open redirects.
Noberus ransomware: Coded in Rust and tailored to victim.
Instagram hijacks all start with a phish.
SysJoker backdoor masquerades as benign updates.
The persistent and patient nature of advanced threat actors.
Use of legitimate tools possibly linked to Seedworm.
A collaboration stumbles upon threat actor Lyceum.
Keeping APIs on the radar: Evaluating the banking industry.
The rise of Karakurt Hacking Team.
Encore: When big ransomware goes away, where should affiliates go?
CyberWire Pro Research Briefing from 12/21/2021.
Discovering ChaosDB, a critical vulnerability in the CosmosDB.
FIN7 repositioning focus into ransomware.
Getting in and getting out with SnapMC.
CyberWire Pro Research Briefing from 11/23/2021
Using bidirectionality override characters to obscure code.
A glimpse into TeamTNT.
An incident response reveals itself as GhostShell tool, ShellClient.
Malware sometimes changes its behavior.
When big ransomware goes away, where should affiliates go?
Groove Gang making a name for themselves.
Taking a closer look at UNC1151.
IoT security and the need for randomness.
Vulnerabilities in the public cloud.
An IoT educational exercise reveals a far-reaching vulnerability.
A Google Chrome update that just didn't feel right.
Like a computer network but for physical objects.
Joker malware family: not a joke for Google Play.
Exploring vulnerabilities of off-the-shelf software.
You can add new features, just secure the old stuff first.
SideCopy malware campaigns expand and evolve.
China's influence grows through Digital Silk Road Initiative.
Free malware with cracked software.
Enabling connectivity enables exposures.
Dealing illicit goods on encrypted chat apps.
Malware in pirated Windows installation files.
Exhibiting advanced APT-like behavior.
Primitive Bear spearphishes for Ukrainian entities.
Taking a look behind the Science of Security.
Bad building blocks: a new and unusual phishing campaign.
EtterSilent: a popular, versatile maldoc builder.
Leveraging COVID-19 themes for malicious purposes.
Jack Voltaic: critical infrastructure resiliency project, not a person.
SUPERNOVA activity and its possible connection to SPIRAL threat group.
A snapshot of the ransomware threat landscape.
Bulletproof hosting (BPH) and how it powers cybercrime.
Social engineering: MINEBRIDGE RAT embedded to look like job résumés.
Strategic titles point to something more than a commodity campaign.
Ezuri: Regenerating a different kind of target.
How are we doing in the industrial sector?
BendyBear: difficult to detect and downloader of malicious payloads.
Keeping data confidential with fully homomorphic encryption.
Diving deep into North Korea's APT37 tool kit.
Shining a light on China's cyber underground.
Attackers (ab)using Google Chrome.
Using the human body as a wire-like communication channel.
"Follow the money" the cybersecurity way.
The Kimsuky group from North Korea expands spyware, malware and infrastructure.
Trickbot may be down, but can we count it out?
Manufacturing sector is increasingly a target for adversaries.
Emotet reemerges and becomes one of most prolific threat groups out there.
Encore: Unpacking the Malvertising Ecosystem. [Research Saturday]
Encore: Seedworm digs Middle East intelligence. [Research Saturday]
Advertising Software Development Kit (SDK): serving up more than just in-app ads and logging sensitive data.
Following DOJ indictment, a look back on NotPetya and Olympic Destroyer research.
SSL-based threats remain prevalent and are becoming increasingly sophisticated.
Encore: Using global events as lures for malicious activity.
Misconfigured identity and access management (IAM) is much more widespread.
That first CVE was a fun find, for sure.
PoetRAT: a complete lack of operational security.
Leveraging for a bigger objective.
The Malware Mash!
Just saying there are attacks is not enough.
Intentionally not drawing attention.
It's still possible to find ways to break out.
Smaug: Ransomware-as-a-service drag(s)on.
What came first, the Golden Chickens or more_eggs?
Election 2020: What to expect when we are electing.
Leveraging legitimate tools.
Going after the most valuable data.
They fooled a lot of people.
Using global events as lures.
Waiting for their victims.
Like anything these days, you have to disinfect it first.
Detecting Twitter bots in real time.
It was only a matter of time.
Every time we get smarter, the bad guy changes something.
Are you running what you think you're running?
Enter the RAT.
Click here to update your webhook.
The value of the why and the who.
Due diligence cannot be done as a one-off.
Twofold snooping venture.
Naming and shaming is the worst thing we can do.
Gangnam Industrial Style APT campaign targets South Korea.
The U.S. campaign trail is actually quite secure.
Fingerprint authentication is not completely secure.
Contact tracing as COVID-19 aid.
How low can they go? A spike in Coronavirus phishing.
Profiling an audacious Nigerian cybercriminal.
A rough year ahead for ransomware attacks - and how to stop them.
Hidden dangers inside Windows and LINUX computers.
The security implications of cloud infrastructure in IoT.
TLS is here to stay.
Overworked developers write vulnerable software.
Application tracking in Wacom tablets.
New vulnerabilities in PC sound cards.
If you can't detect it, you can't steal it.
The Chameleon attacks Online Social Networks.
Tracking one of China's hidden hacking groups.
Know Thine Enemy - Identifying North American Cyber Threats.
Clever breaches demonstrate IoT security gaps.
Profiling the Linken Sphere anti-detection browser.
A Jira vulnerability that’s leaking data in the public cloud.
Inside Magecart and Genesis.
WAV files carry malicious data payloads.
Targeting routers to hit gaming servers.
Mustang Panda leverages Windows shortcut files.
Sodinokibi aka REvil connections to GandCrab.
Monitoring the growing sophistication of PKPLUG.
Usable security is a delicate balance.
Masad Steals via Social Media.
Hoping for SOHO security.
Decrypting ransomware for good.
The fuzzy boundaries of APT41.
Focusing on Autumn Aperture.
Leaky guest networks and covert channels.
Bluetooth blues: KNOB attack explained.
VOIP phone system harbors decade-old vulnerability.
Emotet's updated business model.
Gift card bots evolve and adapt.
Detecting dating profile fraud.
Unpacking the Malvertising Ecosystem.
Package manager repository malware detection.
Day to day app fraud in the Google Play store.
Nansh0u not your normal cryptominer.
Opportunistic botnets round up vulnerable routers.
Giving everyone a stake in the success of Open Source implementation.
Middleboxes may be meddling with TLS connections.
Apps on third-party Android store carry unwelcome code.
Xwo scans for default credentials and exposed web services.
Blockchain bandits plunder weak wallets.
A fresh look at GOSSIPGIRL and the Supra Threat Actors.
Elfin APT group targets Middle East energy sector.
Steganography enables sophisticated OceanLotus payloads.
Sea Turtle state-sponsored DNS hijacking.
Deep Learning threatens 3D medical imaging integrity.
Undetectable vote manipulation in SwissPost e-voting system.
Establishing software root of trust unconditionally.
Lessons learned from Ukraine elections.
Alarming vulnerabilities in automotive security systems.
Ryuk ransomware relationship revelations.
ThinkPHP exploit from Asia-Pacific region goes global.
Job-seeker exposes banking network to Lazurus Group.
Fake Fortnite app scams infect gamers.
Rosneft suspicions shift from espionage to business email compromise.
Seedworm digs Middle East intelligence.
Trends and tips for cloud security.
Online underground markets in the Middle East.
Amplification bots and how to detect them.
Luring IoT botnets to the honeypot.
Magecart payment card theft analysis.
NOKKI, Reaper and DOGCALL target Russians and Cambodians.
Apple Device Enrollment Program vulnerabilities explored.
The Sony hack and the perils of attribution.
Operation Red Signature targets South Korean supply chain.
Getting an education on Cobalt Dickens.
Doubling down on Cobalt Group activity.
Establishing international norms in cyberspace.
Election protection.
Faxploitation.
Stormy weather in the Office 365 cloud.
Driving GPS manipulation.
Cryptojacking criminal capers continue.
Sophisticated FIN7 criminal group hits payment card data.
ICS honeypots attract sophisticated snoops.
Android device eavesdropping investigation.
Leafminer espionage digs the Middle East.
ATM hacks on the rise.
Cyber espionage coming from Chinese University.
Stealthy ad fraud campaign evades detection.
Thrip espionage group lives off the land.
Cortana voice assistant lets you in.
BabaYaga strangely symbiotic Wordpress malware.
Measuring the spearphishing threat.
A new approach to mission critical systems.
No Distribute Scanners help sell malware.
VPNFilter malware could brick devices worldwide.
LG smartphone keyboard vulnerabilities.
Cyber bank heists.
Winnti Umbrella Chinese threat group.
Islamic State propaganda persistence.
UPnProxy infiltrates home routers.
Threat actors hijack Lojack.
Three pillars of Artificial Intelligence.
BlackTDS and ThreadKit offered in criminal markets.
New MacOS backdoor linked to OceanLotus.
InnaputRAT exfiltrates victim data.
Energetic Dragonfly and DYMALLOY Bear 2.0.
Crypto crumple zones.
Chasing FlawedAMMYY.
Code comments cause SAML conundrum.
Cryptojacking injections heat up.
Dark Caracal APT steals out of Lebanon.
Lebal malware phishes for victims.
Phishing for holiday winnings.
The uncanny HEX men.
IcedID banking trojan.
Advanced adware with nation-state tactics.
Targeting Olympic organizations.
Fancy Bear Duping Doping Domains.
Shake Your MoneyTaker.
TRISIS Malware: Fail-safe fail.
Hunting the Sowbug.
Keyboys back in town.
The unique culture of the Middle Eastern and North African underground.
Stealthy Zberp Banking Trojan.
Staying ahead of Fast Flux Networks.
Waiting for Terdot, a sneaky banking Trojan.
Dark Net Pricing with Flashpoint's Liv Rowley.
Taiwan Bank Heist and Lazurus Group with BAE's Adrian Nish.
Exploring Phishing Kits with Duo Security's Jordan Wright.
Tracking a Trojan: KHRAT.
WireX BotNet with Justin Paine from Cloudflare.
Synthesized DNA Malware with Peter Ney.
Android Toast Overlay: Ryan Olson from Palo Alto Networks.
APT 33: FireEye's John Hultquist on an Iranian Cyber Espionage Group.
Pacifier APT : Bitdefender's Liviu Arsene describes a sophisticated, multifaceted malware campaign.
Cobian RAT: Zscaler’s Deepen Desai describes some clever malware.