ShadowTalk: Powered by ReliaQuest cover art

All Episodes

ShadowTalk: Powered by ReliaQuest — 477 episodes

#
Title
1

China Nation State Cyber Espionage: How OP-512 Exploited Legacy IIS Servers and Evaded Detection

2

SonicWall, MFA Bypass, IABs: Why Patched Devices Are Still Handing Attackers Initial Access

3

Device Code, OAuth, PhaaS: How Session Token Theft is Breaking the Phishing Playbook

4

SQLite, Mistral, OpenAI: How AI Attacks Are Reshaping the Attack Surface

5

Canvas, Trellix, Mini Shai-Hulud: How Defenders Respond When Supply Chain Attacks Become Weekly

6

Akira, ShinyHunters, and The Gentlemen: Extortion Lessons From Early 2026

7

What Happened to Black Basta's Playbook? The Automated Teams Phishing Threat Hitting Executives

8

Did ShinyHunters Compromise Vercel? Every CISO's Cloud Security Visibility Problem

9

What Claude Mythos Means for Organizations

10

Axios and Trivy — Supply Chain Gaps Organizations Must Fix

11

Faster, Smarter, and Already Escalated — What It Takes to Defend Against the Modern Threat Landscape

12

The Invisible Attack Surface: Iran-Aligned Threat Actors and Corporate Blind Spots

13

The 2026 Annual Threat Report Breakdown, Part 3: The Long Game — Nation-State Threats & What's Coming in 2026

14

The 2026 Annual Threat Report Breakdown, Part 2 — Once They're In: Post-Compromise Tactics, Ransomware & Exfiltration

15

The 2026 Annual Threat Report Breakdown, Part 1 — How AI Contributes to Attacker Speed, and the Malware That's Winning

16

Malware Isn't Required—How Ransomware Groups Turn Legitimate RMMs Into a Weapon

17

Ransomware vs. Exfiltration-Only—The Extortion Model Showdown

18

Patch Management Is Losing—The Case for Predictive Vulnerability Defense

19

Beyond Phishing Emails—Social Engineering Drives Initial Access

20

Malicious AI—The New Face of Cyber Threats

21

Maintainer Compromise: The Next Supply-Chain Attack Vector in 2026

22

Kicking Off 2026 with Ransomware Insights and Defense Strategies

23

React2Shell Attacks Evolve, ClickFix Attacks, and Holiday Season Threats

24

React2Shell Exploits, CISA’s Brickstorm Warning, ShadyPanda’s Browser Weaponization

25

Scattered Lapsus$ Hunters, SilverFox's ValleyRat Campaign, and More

26

Are Cyber Predictions Worth It? Plus Chinese AI Attacks, IoT Takeovers

27

Fortinet Flaw Exposed and Exploited! Plus, Threat Hunter Hacks: SEO Hits Hard

28

Gootloader's Return, LANDFALL Android Spyware, Sector-by-Sector Cyber Trends

29

Why Cloud Threats Are Escalating: Identity Risks, Automation Flaws, and Legacy Vulnerabilities, Plus the Latest on Chinese APT Campaigns and NPM Package Abuse

30

Why Cyber Threats Surge 20% During M&A, Plus the Latest on Qilin and Lazarus Group Campaigns

31

Automate to Defend: A Former FBI Agent's Ransomware Guide for CISOs

32

Is Your Software a Secret Backdoor? Flax Typhoon's Latest Campaign Unwrapped

33

Cl0p's Latest Heist: Exploiting Oracle's Critical Vulnerability

34

Should Governments Hoard Zero Days? Analyzing Brickstorm Malware and Storm-1849

35

Attacker Breakout Time Hits 18 Minutes, New Shai-hulud NPM Worm

36

Welcome to ShadowTalk

37

Do You Need AI to Fight AI? Plus Supply-Chain Attacks and Russia's Latest Backdoor

38

Salesforce Attack Fallout, Axios Abuse, and Cloud Ransomware

39

New Silk Typhoon Attacks, the Cybercriminal Recruitment Underworld, and More!

40

Warlock Ransomware Hits Telecoms, LLM Data Theft, and ShinyHunters Updates

41

ShinyHunters, Scattered Spider, and Salesforce? Plus, Kimsuky Data Breach!

42

Akira’s Zero-Day Chaos + The Rise of DRP Threats

43

Full CrushFTP Attack Chain, Plus BreachForums is Back!

44

New SharePoint Flaw, How Cybercriminals Use AI

45

Do You Really Need IOCs? Plus Zero-Day Exploits, AI Data Leaks, and Phishing for VIPs

46

SafePay Ransomware Rises, North Korea Adopts ClickFix

47

Citrix Bleed 2, Scattered Spider Hits Aviation

48

Analyzing Iran-Israel Cyber Threats, New Scattered Spider Attack Chain

49

Israel-Iran Cyber Warfare, Anubis Ransomware, and More Attacker Trends

50

Black Basta's Enduring Legacy, Qilin Exploits Fortinet Flaws

51

Scattered Spider's Evolving Playbook, SentinelOne Outage

52

SPECIAL: How Russian Market Fuels Credential-Based Attacks

53

The Threat Evolution: SAP Exploits, SEO Poisoning, and SkitNet Malware

54

Will US Politics Reshape Russian Cyber Threats?

55

Scattered Spider Strikes Again, Hunt for North Korean Insiders Heats Up

56

Demystifying CVE-2025-31324, The New Critical SAP NetWeaver Flaw

57

BreachForums Down: Hacktivist Attack or FBI Crackdown?

58

Hijacked and Hidden: ReliaQuest Identifies New Backdoor and Persistence Technique

59

Fast Flux DNS Challenges, Evolving Adversary Tactics, and Proactive Defense Strategies

60

From Oracle to AI: Everything You Need to Know About Emerging Cyber Threats

61

Guest Episode: Navigating Cyber Storms with Expert Insights on Incident Response

62

When Old Meets New: The Rise of VPN Exploits and Brute-Force Tools

63

Webcam Warfare, Supply Chains Under Siege, Insider Threats, and More!

64

Hooked and Hacked: Phishing Frenzy, Ransomware Recap, Zero-Day Fallout

65

SPECIAL: 'From Data to Defense' - Insights from ReliaQuest's Annual Cyber-Threat Report

66

BlackLock Ransomware, 8Base Seized, Storm-2372 Phishing

67

Brute Force Campaign, Ransomware Insider Recruiting, Manufacturing Threats

68

AI Spies, Unused AWS Buckets, New Lazarus Group Infrastructure

69

Attackers Accelerating Attacks, Lumma Infostealer, DeepSeek LLM

70

Ransomware Hits New Heights, FortiGate Data Leaked, Sneaky 2FA Phishing Kit

71

Guest Episode: Ways Threat Intel Can Prioritize Threats, Vulnerability Chaos, Biden Executive Order

72

Espionage Hits US Treasury, OtterCookie Tricks Jobseekers, ReliaQuest Tackles Pure Malware

73

Guest Episode: Are Cyber Predictions Worth It? Clop Strikes, BADBOX Crumbles, US Fights Back Against Chinese Espionage

74

Termite Ransomware, QR-Code Browser Bypass, CAPTCHA Hijacking

75

BootKitty Unleashed, Word Corruption Campaigns, M&A Cyber Threats

76

Guest Episode: Can Someone Non-Technical Be a CISO? New APT28 & Palo Alto Exploits

77

Black Friday Retail Risks, T-Mobile Troubles, AI Deceptions

78

2025 Cyber Threat Predictions, MOVEit Data Breach, Volt Typhoon Rebuilds

79

Credential Theft, LastPass Social Engineering, Interlock Ransomware

80

Guest Episode: Black Basta's TTP Shift, Diversity, Equity, and Inclusion (DEI) In Cyber Security

81

Scattered Spider x RansomHub, Anonymous Sudan Unmasked, APT41 Gamble

82

Ransomware in Q3 2024, Cisco Breached, ChatGPT Misuse

83

Healthcare Cyber Threat, Salt Typhoon Compromises US Telecoms, Gorilla Botnet DDoS Campaigns

84

Guest Episode: Importance of Cyber Insurance, Embargo Ransomware Target Cloud, Influence Ops Target US Election

85

Telegram's Pivot, Kaspersky's Surprise, Remediating Data Exfiltration Attacks

86

Fortinet Breach, Malware Locks Users in "Kiosk" Mode, Insider Threat Case Studies

87

GRU Orchestrate Sabotage and Assassination, Sextortion Scams, Inc. Ransom's Novel Attack

88

Guest Episode: Building Security Teams, Ransomware and Lawsuits, Top Attacker Techniques

89

Telegram CEO Arrested, Volt Typhoon, Cybercriminal Forum Insights

90

NPD Breach Latest, Election Disinformation, Service Account Abuse

91

Unusual Espionage, Vicious Vulnerabilities, Popular Exfiltration Tools and Malware Loaders

92

Special: LIVE from BlackHat 2024, Unauthorized RMM Useage, DEF CON 32 Preview

93

Deepfakes-The New Frontier in Deception, Ransomware Roundup, Threats Bypassing Your EDR

94

CrowdStrike Global IT Outage, Finance & Insurance Threats

95

Guest Episode: Ransomware in Q2 2024, Disney/AT&T Breach

96

GenAI Powers Cybercrime, Cobalt Strike Takedown, Record-breaking DDoS Attack

97

Weekly: TeamViewer Supply Chain Attack, MOVEit Horrors, Medusa Ransomware Case Study

98

Weekly: Lockbit Claim US Federal Reserve Breach, Protocol Tunneling, Kaspersky Banned in US

99

Weekly: Future of Scattered Spider, Supply Chain Compromise, Insider Threats

100

Guest Episode: Cyber Threats Facing Healthcare, Optum Impact, Ransomware, AI and Automation

101

Special: Live from InfoSec Europe 2024, Snowflake Breach, Cybercriminal AI reflections

102

Weekly: Microsoft Deprecates VBScript, Common Infostealers, GhostEngine Cryptominer, BlackSuit Attack Analysis

103

Weekly: Microsoft Enforce MFA, Fileless Malware, Rise of Deepfakes

104

Weekly: Ransomware Impacting Hospitals, Q1 Most Observed Attacker Techniques, BreachForums Advertise Access to Security Company

105

Special: AI and Automation at RSAC 2024

106

Cracking the Code: Getting a Job in Cybersecurity

107

Weekly: APT28 Activity, Iran/Israel Tensions, Ransomware Rebrands

108

Weekly: Palo Alto Critical Exploit, VPN Management, RansomHub Leak Optum Data

109

Weekly: HC3 Social Engineering Warning, ReliaQuest Q1 Phishing Report, Microsoft Copilot

110

Weekly: New Backdoor in XZ Utils, SEO Poisoning, Impersonation Scams

111

Weekly: Google AI Search, Spain Telegram Ban, Speculative Execution Vulnerabilities

112

Weekly: AT&T Breach, Magnet Goblin, ReliaQuest's Annual Threat Report (ATR)

113

Weekly: TeamCity and Supply Chain Risk, BEC Detections, Midnight Blizzard

114

Weekly: ConnectWise Critical Vulnerabilities , Credential Theft, NIST Frameworks

115

Weekly: Lockbit Return, SAT Exercises, Optum Breach

116

Weekly: Lockbit Taken Down, RMM Tool Abuse, Chinese Gov't Documents Exposed

117

Weekly: SocGholish, Volt Typhoon, ToothBrush DDoS' and Flipper Zero

118

Weekly: AnyDesk Breach, Deepfake Social Engineering, Q1 2024 Priorities

119

Weekly: Killnet 2.0, Baselining Detection Rules, Ransomware in Q4 2023

120

Weekly: Midnight Blizzard Targets Microsoft, Recent Attacker Techniques, Citrix NetScaler Vulnerabilities

121

Weekly: Ivanti Zero-days, Valid Account Misuse, Emerging risk from (IoT) devices

122

Weekly: Cyber Threats Developments of 2023, Lockbit Targets Healthcare

123

Weekly: 2023 in Review, ALPHV Targeted by FBI, Predictions for 2024

124

Weekly: BYOVD Report, Log4Shell Two Years Later, ALPHV Site Outage, Delaying SEC Disclosures

125

Weekly: Ransomware Targeting ESXi, Threats to Airline Organizations, CNI Impacted

126

Weekly: EDR Pitfalls, Okta Intrusion Update, Secure AI Guidelines, Expired Google Cookies

127

Weekly: ALPHV SEC Complaint, Scattered Spider Case Study, Sandworm Attacks

128

Weekly: CitrixBleed, Taking a Proactive Approach to IR, BiBi wiper targets Israeli Organizations

129

Weekly: Apache ActiveMQ and Atlassian Confluence, SEC files charges, QR code phishing

130

Weekly: SolarWinds SEC Charges, Vulnerabilities Roundup, AI Executive Order

131

Weekly: Q3 Ransomware Report, ServiceNow Vulnerability, Okta Incident

132

Weekly: Critical CISCO IOS XE Vuln, Business Email Compromise (BEC) activity, malicious use of Discord

133

Weekly: Hamas Cyber Threat Implications, Top Adversary Techniques, Qakbot

134

Weekly: National Cyber Security Awareness Month (NCSAM), Progress FTP Server, RDP Sessions, IronNet

135

Weekly: Hunting for MFA bypass techniques, Libwebp Vuln exploited, VMWare ESXi

136

Weekly: MFA Bypass Techniques, Microsoft Data Leak, Latest ALPHV Attack

137

Weekly: Anonymous Sudan, Domain Redirection Attacks, UK Ransomware Report and Managed Engine Zero-Day Exploit

138

Weekly: SocGhoulish deep dive, AI security concerns, LockBit vs. UK MOD

139

Weekly: Qakbot Takedown, New Barracuda Zero-Day, Resurgence of Hacktivism

140

Weekly: Malware Loaders, Ransomware Runbooks, Generative AI and Barracuda ESG

141

Weekly: DefCon, Cl0p, Raccoon Stealer

142

Weekly: AI at BlackHat, Device Code Phishing, Russia-Ukraine War Trends and DEF CON Tips

143

Special: CISO Chat Live from BlackHat 2023

144

Weekly: Business Email Compromise (BEC), ReliaQuest Bi-Annual threat reports, influence of AI on the Cyber Threat Landscape

145

Weekly: What We're Seeing Right Now, Cl0p Cycle Continues, Ivanti Zero-Day, ALPHV API

146

Weekly: What We're Seeing Right Now, Cl0p Update, WormGPT

147

Weekly: Microsoft Cloud Breach, Strava App, Cl0p Update and Remote Management Monitoring

148

Weekly: Defense Evasion via Virtualization, LockBit target TSMC, CISA Identify New Exploited Vulnerabilities

149

Weekly: Legal Developments, New APT29 Campaign and ReliaQuest's Annual Threat Report

150

Weekly: Cl0p update, Killnet target European financial institutions, closed sources findings

151

Weekly: Cl0p releases company names, Gootloader, new Fortinet RCE, Ukrainians hackers take down Infotel.

152

Weekly: MOVEit Zero-day and Cl0p attribution, Infostealing ecosystem, DBIR 2023 Report

153

Weekly: MOVEit Zero-day, RaidForums Breach, Buhti Ransomware

154

Weekly: GootLoader, Intrusion Truth, Volt Typhoon, and Exponent conference debrief

155

Weekly: SocGholish, Cactus Ransomware, Greatness Phishing-as-a-service

156

Weekly: Snake malware takedown, Kubernetes hunts, and Caffeine Phishing-as-a-Service

157

Weekly: ReliaQuest Threat Management, ALPHV, Veeam Vulnerability Exploited

158

Weekly: RQ Ransomware Report, 3CX Update, Russia-Ukraine Cyber Operations, and Cybercriminal Ecosystems

159

Special: RSA Conference 2023

160

Weekly: Vulnerability Quarterly Roundup, Domino Backdoor, Lockbit Targeting MacOS

161

Weekly: Cobalt Strike takedown, latest MERCURY campaign, Patch Tuesday

162

Weekly: Genesis Market seizure, Vulkan Files, and new Microsoft Security Update

163

Weekly: 3CX supply chain attack, Rostec deanonymize Telegram, IcedID

164

Weekly: Outlook Vulnerability, TeamTNT and Breachforums closure

165

Weekly: SVB collapse, FBI IC3 report, and Cl0p update

166

Weekly: US National Cybersecurity Strategy, Emotet and Cl0p return

167

Weekly: HTML Smuggling, CISA Guidance on Logging

168

Weekly: Russia-Ukraine War - One-Year Later

169

Weekly: Trickbot/Conti Sanctions, OneNote Documents, and NATO DDoS Attacks

170

Weekly: VMware ESXI campaign and SocGholish overview

171

Weekly: Hive Ransomware Takedown and Dark Web Cybercriminal Jobs

172

Weekly: Ransomware Profits Drop, Russian ISP, and Microsoft Investigation

173

Weekly: 2022 Recap and Forecasting 2023 Trends

174

Weekly: Turla Target Ukraine, ChatGPT, and Lorenz Ransomware Activity

175

Weekly: Welcome to 2023!

176

Weekly: Recent Vulnerabilities, Clop Ransomware, New Year's Resolutions

177

Weekly: Russian and Ukraine Roundup, Lazarus Group Cryptocurrency Activity, Apple’s Right to Repair

178

Weekly: Sandworm targets Ukraine, Oracle RCE vulnerability, 300th Episode

179

Weekly: LockBit Arrest, Tech Layoffs, Black Friday Risks

180

Weekly: APT29 Credential Roaming, Russian Hacktivists Use Somnia Ransomware, Recent LockBit Activity

181

Weekly: British Government Scanning UK Devices, Twitter's Verification Process, Latest Emotet Return

182

Weekly: APT10 Deploy LODEINFO Malware, New Azov Data Wiper, Emotet Malicious Spam

183

Weekly: Ukraine Activity Roundup, Vice Society Targeting Schools, Iranian Hacktivism

184

Weekly: REvil connection to Ransom Cartel, Cryptocurrency hacks in Japan by Lazarus, Toyota T-Connect Attack

185

Weekly: US Airports DDoS’d, Fortinet Vulnerability, Deep Dive Into Information Stealers

186

Rick Holland with Michael Farnum & Greg Porterfield of Set Solutions: Uber breach & 2023 predictions

187

First use of LockBit Builder, Ransomware Groups Destroying vs. Encrypting Data, Domain Shadowing

188

LockBit Builder leak, Lapsus$ breaches Rockstar and Uber, Emotet pushes Quantum and Alphv ransomware

189

Weekly: Intermittent Encryption Tactics, Geopolitical Developments in Cyber Crime

190

Weekly: Revival of Hacktivism, Targeting the Education Sector, Terror NFTs

191

Weekly: LastPass Incident, Montenegro Attacks

192

Weekly: Cyber Threat Insurance, LockBit’s lockdown, Charming Kitten email attack

193

Weekly: BlackHat and Defcon Recap, Microsoft’s Patch Tuesday, North Korea Fake Coinbase Jobs

194

Weekly: A History of Ransomware, deBridge Hack Details, Advice for Multiple Ransomware Attacks

195

Weekly: 911 Proxy Service Ends, ALPHV claims attack on pipeline and Recent news from Taiwan & China

196

Weekly: Entrust Ransomware Attack, Coinbase Insider-Trading Case and Redeemer Ransomware Builder

197

Weekly: North Korea Makes Comeback with Ransomware, How Malware is Distributed, Russia Fines Google

198

Weekly: Microsoft Patch Tuesday, Russia Targeted, Hive Ransomware Upgrade, TrickBot Attacks Ukraine

199

Weekly: Chinese Data Leaked, Crypto Scam Targets British Army, Bug Bounty Reports Insider Threat

200

Weekly: Cyber Threat Intelligence Aids Ukraine, Conti Stops Data Leak, LockBit's New Bounty Program

201

Weekly: AlphV Publishes Victims' Data, 'BidenCash' Website Sells Credit Card Info, ATO Paper

202

Weekly: Follina Zero Day, Conti Shuts Down Affiliate Program, LockBit vs Mandiant Discussion

203

Weekly: LockBit PR Stunt Against Mandiant and Bohrium Targeted Users Via Spear-Phishing Operations

204

Special: Geoff White and the Lazarus Heist

205

Special: David Thejl-Clayton Talks Rolling Your Own Verizon DBIR

206

Weekly: Insider Threat Actor is Sentenced, Microsoft Patch Tuesday Mishap and NFT Scams

207

Weekly: Costa Rica Declares State of Emergency, EU Accuses Russia of Attack, 5 Years Since WannaCry

208

Weekly: The Return of REvil, China APT Activity, Russia-Ukraine RoundUp

209

Weekly: The Return of Lapsus$, 2 Months of Russia-Ukraine War

210

Weekly: Connection Found Between Conti and Karakurt, ICS Networks Targeted, Lazarus Uses Crypto Apps

211

Weekly: Cybercriminal Forums Go Down & Cyber Activity in the Russia-Ukraine War Go Up

212

Weekly: Spring4Shell, Borat RAT, FIN7 Evolves Toolset

213

Special: Structured Analytical Techniques and Office Banter

214

Especial: Desvendando o Grupo de Hackers Lapsus$

215

Weekly: Q1 Review Including Russia-Ukraine War, REvil Arrests, Emergence of Lapsus$ & More!

216

Especial: Lapsus$, Sus Ataques, y La Brecha de Okta

217

Weekly: Lapsus$ Targets Large Companies, Russia/Ukraine Ongoing War, TransUnion Data Breach

218

Special: Russia-Ukraine War Update 22 March 2022

219

Weekly: New Malware "CaddyWiper", Crypto ATM, Russia to Use TLS Certificates

220

Weekly: Linux Vulnerability "Dirty Pipe", 2022 Ransomware Landscape So Far, Coinbase Blocks Russia

221

Special: Russia-Ukraine War Update 07 March 2022

222

Especial: Rusia y Ucrania Guerra, SWIFT, y Consejos de Mitigación y Reducción del Riesgo

223

Weekly: Conti Leaks, Reactions from Cybercriminals, & Priority Intelligence Requirements

224

Special: Russia-Ukraine War Update 02 March 2022

225

Special: Russia and Ukraine - What We Know So Far - 28 February 2022

226

Weekly: Russian Offensive Cyber-Team, Conti-Trickbot, OpenSea NFT Breach, & More!

227

Special: Russia and Ukraine Conflict

228

Weekly: US DoJ Indictment, Grey Hat & ETH's Bounty, Crypto Ads

229

Weekly: Microsoft to Enable Macros in Office, Russia Arrests Hacking Group, Valentine's Day Concerns

230

Weekly: Cyber Operations As Part of Hybrid Warfare in Russia-Ukraine Context

231

Weekly: Malicious QR Codes, Ransomware Insider Attacks, Russia/Ukraine Conflict Escalates

232

Weekly: Attacks Against Ukrainian Websites, REvil Arrests, and Microsoft Wiper

233

Weekly: H2 Database Vulnerability, DDoS Extortion, and Alternate ransomware techniques

234

Especial: Servicios financieros, ransomware, y ciberdelincuencia

235

Weekly: Closing out 2021 with Log4j Updates, Karakurt News, and a Cybercriminal Arrest

236

Special: Log4j Zero-day Vulnerability

237

Weekly: NICKEL Targets LATAM and Europe, Quantum Computing, and UK Cyberattack

238

Weekly: IKEA Hack, Sabbath Ransomware Group, Proofpoint Rich Text Format and More!

239

Weekly: GoDaddy Breach, MosesStaff Political Attacks, and Conti Orchestrates Emotet Comeback

240

Weekly: Exploit-as-a-Service, Emotet’s Return, and FBI Fake Email Campaign

241

Special: NCSAM Takeaways and Key Resources

242

Weekly: Robinhood data leak, NSO in US Appeals Court and Iranian-linked hackers target ISPs

243

Weekly: NRA under the gun, Groove hoax, and Conti gulf apology

244

Weekly: NOBELIUM is back, Ransomware Decryptors and Employers, and Spooky Halloween Tales

245

Weekly: REvil Rep Death, Ransomware Trends, and BlackMatter Advisory

246

Weekly: FIN12 targets healthcare, Google Phishing, and Pentagon Official Resigns

247

Weekly: Twitch Hack, Facebook blackout, and Pandora Papers

248

Weekly: NOBELIUM Malware, BEC scheme, and EU Condemns Russian Cyberactivity

249

Weekly: FBI under fire, Microsoft goes passwordless, and RaidForums

250

Special: Dr. Tom Robinson - Threats to Crypto and Tracking Ransomware with Blockchain Analytics

251

Weekly: Mozi arrest, Fortinet credentials, and Splunk PowerShell Release

252

Weekly: ProxyToken and Lockfile, AlphaBay’s Comeback

253

Weekly: #tbt Throwback Thursday Edition

254

Weekly: Prometheus, Ransomware Updates, and Microsoft Morse Code

255

Weekly: Phishing Site Targets Scammers, China Pulls False Flag in Israel, $600 Million Crypto Hack

256

Weekly: Wiper Malware Targets Tokyo Olympics, MeteorExpress Attack, PwnedPiper, Hopper and More!

257

Weekly: CISA guidelines, Q2 Ransomware roundup, and PunkSpider’s back!

258

Weekly: Microsoft Exchange attribution, NSO Spyware, Zero-days, and Clippy

259

Special: Bryson Bort, Cyber Gandalf and MORE!

260

Weekly: Kaseya Attack Updates, Fancy Lazarus, and Spyware on Google Play

261

Weekly: LinkedIn Breach, Marketo Marketplace, Playstation Breach, Western Digital MyBook, Nobelium

262

Special: Cyber Threat Intel Leader Gert-Jan Bruggink, legos, and MORE!

263

Weekly: Google Releases Supply-Chain Framework, New NATO Agreements, and More!

264

Special: Pulsedive Founders Dan and Grace Talk Origins, IOCs, and More

265

Weekly: VPN Vulnerabilities, EA Gets Attacked, Plus Clop Deals With Affiliate Arrests

266

Special: Anomali’s AJ Nash Talks Origin Story, Building Threat Intel Teams, and More!

267

Weekly: Chinese Cyber Espionage, GitHub Takedowns, and EURO 2020 Predictions

268

Weekly: Nobelium Attacks, VMWare Exploits, and the Biden Administration’s Letter on Ransomware

269

Special: The State of the APAC Cyber Threat Landscape

270

Weekly: Drug Kingpin Taken Down by Cheese and Ransomware Makes a Comeback

271

Special: Jeff Stone Discusses His Origin Story, Interviewing Cybercriminals, and More!

272

Weekly: Colonial Pipeline Updates, DarkSide Feels the Pressure, and More!

273

Weekly: The Colonial Pipeline Incident, BEC Gift Card Campaigns, and More!

274

Special: David Thejl-Clayton Talks Data Driven Incident Response and Verizon DBIR

275

Weekly: VPN Vulnerabilities, Supply Chain Attacks, and Babuk Says “Bye”!

276

Special: Amy Bejtlich Talks Culture of Candor Within Intel Teams and More!

277

Special: ShadowTalk’s 200th Episode!

278

Weekly: Supply Chain Attacks Rule The Day, Plus The FBI Takes On Web-Shells

279

Weekly: Q1 Ransomware Round-Up - Looking Back at Early 2021

280

Weekly: Facebook Data Breach, Ransomware Cartel, and More!

281

Weekly: It’s A Ransomware Round-Up - CNA , Clop, and Much More!

282

Special: Dr. Chase Cunningham Talks Zero Trust, His Book on Cyber Warfare, and More!

283

Weekly: More on Microsoft and Acer Receives $50 Million in Ransom Demands

284

Special: Creator of Zero Trust John Kindervag Talks Origins and the Future of Zero Trust!

285

Weekly: Ransomware Resurgence - The Return of FIN8, DarkSide, and More!

286

Weekly: Supply Chain Compromise Round-Up - Microsoft, Verkada, and More!

287

Weekly: New Australian Legislature, VMware Bugs, and More!

288

Weekly: When Initial Access Brokers Attack

289

Weekly: Egregor Arrests, SIM-Swapping, and Oldsmar Updates!

290

Weekly: Ransomware Updates - CDPR Victimized, Ziggy’s End, and the Oldsmar Water Incident

291

Weekly: Lebanese Cedar, Nefilim Ghost Credentials, and More on SolarWinds and Emotet

292

Weekly: Law Enforcement Wins the Week - The Fall of NetWalker and Emotet!

293

Weekly: CISA Security Advisory, IObit Attack, and more SolarWinds!

294

Weekly: Sunburst, Sunspot, and more on SolarWinds!

295

Weekly: SolarWinds Updates, TicketMaster Fraud, Apex Cyber Attack, and More!

296

Weekly: SolarWinds Supply-Chain Attack Round-Up

297

Weekly: FireEye Breach, Phishing for the Covid-19 Vaccine, and More!

298

Special: Guest Brian Wrozek Talks Origin Story, Planning for 2021, and More!

299

Weekly: Gootkit & REvil, Spam Haus Findings, and More!

300

Weekly: Egregor Ransomware, IoT Regulations, Black Friday Threats and More!

301

Weekly: FunnyDream, Ragnar Locker on Facebook, and Egregor Ransom Notes

302

Weekly: RegretLocker, OceanLotus, Millions Seized in Cryptocurrency, and more!

303

Weekly: Election Update, Kimsuky Activity, Maze Group Announces Closing, Wroba Mobile Malware

304

Special: Guest Phillip Wylie Talks Origin Story, Bear Wrestling, and Much More!

305

Weekly: The Team Gets Spooky with Fancy Bear, Ryuk, and More!

306

Weekly: SandWorm Indicted by DOJ, Darkside Has A Soft Spot, and Ryuk's Super Speedy Attack!

307

Weekly: Microsoft Derails Trickbot, Ransomware Running Rampant, Fitbit Customers At Risk, and More!

308

Special: Guest Marcus Carey Talks Origin Story, BBQ, Diversity, and More!

309

Weekly: Sanctions from the DOT, Fancy Bear Targets the US Government, and Foreign Spies in Disguise!

310

Weekly: It’s A Ransomware Roundup: Mount Locker, Old Gremlin, REvil, and More!

311

Weekly: Law Enforcement Cracks Down On Cybercriminals, Fancy Bear Goes Phishing, And More

312

Special: Discussing Deception with Chris Sanders

313

Weekly: Ed Merrett Joins To Talk HackableYou And The Latest In Threat Intel

314

Weekly: The Team Talks Baka, Epic Manchego, and Smaug, Plus Emotet Rides Again

315

Weekly: New Zealand Stock Exchange faces DDoS, Tesla avoids cyberattack, and Pioneer Kitten updates

316

Weekly: Photon Team Talks BeagleBoys, DarkSide, and DeathStalker, oh my!

317

Special: Guest David Bianco Talks Origin Story, Pyramid of Pain, and More

318

Weekly: Emotet Gets a Vaccine, NSA Drovorub Advisory, and North Korean Activity plus Bureau 121

319

Weekly: Defaced Subreddits, Intel Leak Drama on Twitter, and HIBP Goes Open-Source

320

Weekly: CWT pays ransom, data leaked for 900+ Pulse Secure Servers, EU issues first cyber sanctions

321

Special: Guest Geoff White Talks Best-Selling Book Crime Dot Com

322

Weekly: Garmin ransomware attack, QSnatch malware, and ShinyHunters Stage 2

323

Weekly: Trickbot trojan mishaps, Emotet resurgence, Twitter takeovers, and APT group updates

324

Weekly: Twitter takeovers, Data Viper breached by NightLion, and a look at CryptBB

325

Weekly: PAN-OS Vulnerability, Lazarus Group, BEC scammer “Hushpuppi”, and New Photon ATO Research

326

Weekly: Torigon, Nulledflix, and BlueLeaks, Plus DevSecOps Insights From DS CISO Rick

327

SPECIAL: Guest Speaker Tom Schmitt Talks About His Origins in Cyber Threat Intel and TITO

328

WEEKLY: Lookback Operators Deploy New Malware Against US Utilities Sector And Honda Cyber Attack

329

SPECIAL: What Goes Into The Verizon DBIR With Alex Pinto

330

WEEKLY: Maze Ransomware Alliance, EndGame DDoS Protection Tool, And Ransomware Disguises

331

WEEKLY: Hacktivist Chooses Destruction Over Profit w/ Ransomware and Collection 1 Hacker Identified

332

WEEKLY: Verizon DBIR, ShinyHunters, Sodinokibi Ransomware, And More Phishing

333

SPECIAL EPISODE: Contact Tracing and COVID-19

334

SPECIAL EPISODE: Remote Worker Security: Tech & ISP Providers, Data Security, And The Future

335

WEEKLY: WannaCry Anniversary, Wordpress Plugin Vuln, WeLeakData Compromised

336

WEEKLY: Competitions On English Forums, Purple Teaming, & Hacker Bribes 'Roblox' Insider

337

SPECIAL EPISODE: The Human Element Of Cybersecurity Programs With Hacker Valley Studio

338

WEEKLY: Microsoft Teams ATO Vulnerability, APT32, & Uptick In Ransomware

339

WEEKLY: Maze Ransomware Infiltrates Cognizant, Czech NCISA Warning, And Third Party Risk Assessment

340

WEEKLY: SFO Airport Hack, Fin6, And Sodinokibi Switching From Bitcoin To Monero

341

WEEKLY: COVID-19 Third Party App Risks, Zoom, And DarkHotel Hackers

342

WEEKLY: Zoom Zero-Day Vulnerabilities and Fin7 Delivering Malware Via Snail Mail

343

WEEKLY: Remote Worker Threat Model And Cybercrime Updates

344

WEEKLY: Slack Vulnerability, Apollon Dark Web Exit Scam, And Online Brand Protection

345

SPECIAL EPISODE: Coronavirus: Cybercrime Reactions And CISO Advice

346

WEEKLY: Necurs Botnet, SMB Vulnerability, Coronavirus Scams, And Dark Web Updates

347

WEEKLY: Banking Trojan Steals Google Authen Codes, Ransomware Attacks Epiq, & Tesco Clubcard Fraud

348

SPECIAL EPISODE: FBI Releases Its Internet Crime Complaint Center (IC3) Report 2019

349

WEEKLY: Data Breaches, Stalkerware, and Dopplepaymer ransomware

350

WEEKLY: OurMine hacks FC Barcelona & Olympics twitter handles, Adsense email extortion, & phishing

351

WEEKLY: yOurMine, Equifax Indictment, and SWIFT POC attack

352

SPECIAL EPISODE: Threat Report ATT&CK Mapping (TRAM) With MITRE’s Sarah Yoder & Jackie Lasky

353

WEEKLY: CTI Frameworks, Wawa Breach Updates, APT34, And Coronavirus Phishing Scams

354

WEEKLY: SANS CTI Summit, Snake Ransomware, CacheOut, And Citrix Vuln Update

355

WEEKLY: Citrix Vulnerability, Microsoft Data Breach, and Telnet Credentials Published

356

WEEKLY: NSA Vulnerability Disclosure, Ransomware News, And Iran Updates

357

WEEKLY: Iranian Cyber Threats, Travelex Ransomware Attack, And Exploit Forum Updates

358

SPECIAL EPISODE: Iranian Cyber Threats: Practical Advice From CISO Rick Holland

359

Jingle Bell Ryuk: NOLA Ransomware, Ring Doorbells, And 2020 Predictions

360

Tochka Dark Web Market Offline, Market.ms Closes, And Data Leakage Stories

361

Cybercriminal Forum Research, Mixcloud Breach, and International Crackdown On RAT Spyware

362

Black Friday Deals On The Dark Web, Phineas Fisher Manifesto, And DarkMarket

363

BSidesDFW Recap, Dynamic CVV Analysis, And The Facebook Camera Bug

364

BlueKeep Attacks, Megacortex Ransomware, and Web.com Breach

365

7.5M Adobe Creative Cloud User Records Exposed, City Of Joburg Ransomware Attack, and APT28 Updates

366

Avast Breach Attempt, NordVPN Breach, And Wifi Security Risks

367

Singapore Cyber Threat Landscape Updates 1H 2019

368

Typosquatting and the 2020 U.S. Election, Honeypots, And Sudo Vulnerability

369

Iran-Linked APT35, Skimming By Magecart 4, Rancour, And Emotet Resurgence

370

The Tyurin Indictment- Mapping To The Mitre ATT&CK™ Framework

371

Magecart Five Widens Attack Vectors, Targeting of Airbus Suppliers, & Tortoiseshell Developments

372

Tortoiseshell Targets IT Providers, The Tyurin Indictment, And Emotet’s Return

373

NCSC Threat Trends And Ransomware Updates

374

Purple Teaming: An Interview With Eliza May Austin

375

Metasploit Project Publishes Exploit For Bluekeep, plus APT3 and Silence Cybercrime Group Updates

376

Ryuk Ransomware, Twitter Rids SMS Tweets, And Facebook Records Exposed

377

More Sodinokibi Activity, Imperva Breach, And Weirdest Food At The Texas State Fair

378

Approaching Cybersecurity As A Third Party Defense Contractor

379

Texas Ransomware Outbreaks And Phishing Attacks Using Custom 404 Pages

380

Breach! Exploring The Modern Digital Breach With Cyber Defense Lab’s CEO Bob Anderson: Part 2

381

Nightmare Market In Disarray And SEC Investigation Into Data Leak At First American Financial Corp

382

Breach! Exploring The Modern Digital Breach With Cyber Defense Lab’s CEO Bob Anderson - Part 1

383

Capital One Breach, Ransomware Trends, and Threat Actors

384

2FA - Advice For Deployment & A Technical Assessment

385

More BlueKeep updates, FSB contractor hacked, and the Enigma Market

386

Interview With Dir Of Threat Intelligence At McDonalds, Brian Hillegas

387

FaceApp Overblown, BlueKeep Updates, And Libra’s Lawmaker Showdown

388

Interview With Deputy CISO At Accenture, Jason Lewkowicz

389

TA505 Global Attacks, Zoom 0-Day, and New Magecart Activity

390

Marriott Faces GDPR Fines - A DPO and CISO Discussion

391

Operation Soft Cell, Libra Cryptocurrency Impersonations, and New Cyber Espionage Activity

392

Google Calendar Phishing, Exim Email Server Vulnerability, and Diversity in Cybersecurity

393

XMRig Cryptocurrency Mining, FIN8 Backdoor, and Attacks Against Office 365

394

“HiddenWasp” and “BlackSquid” malware, TA505 and Turla actvity, and Too Much Information: The Sequel

395

JasperLoader, APT28 URL shortening, and RDP vulnerability discussion

396

CVE-2019-0708 RDP vulnerability and GDPR’s anniversary

397

ElectricFish malware attributed to "Lazarus Group"

398

“Buckeye” APT group used Equation Group tools before 2017 leak

399

Weekly Intelligence Summary: Ep 17

400

Weekly Intelligence Summary: Ep 16

401

Weekly Intelligence Summary: Ep 15

402

Weekly Intelligence Summary: Ep 14

403

Weekly Intelligence Summary: Ep 13

404

Weekly Intelligence Summary: Ep 12

405

Episode 60: Cyber Risks and High-frequency Trading

406

Weekly Intelligence Summary: Ep 11

407

Weekly Intelligence Summary: Ep 10

408

Episode 59: Practitioner’s Guide to Email Spoofing

409

Weekly Intelligence Summary: Ep 9

410

Weekly Intelligence Summary: Ep 8

411

Weekly Intelligence Summary: Ep 7

412

Episode 58: A Tale of Epic Extortions

413

Weekly Intelligence Summary: Ep 6

414

Weekly Intelligence Summary: Ep 5

415

CISO Spotlight: Security Goals and Objectives for 2019

416

Weekly Intelligence Summary: Ep 4

417

Weekly Intelligence Summary: Ep 3

418

Weekly Intelligence Summary: Ep 2

419

Episode 57: Singapore Healthcare Breach

420

Weekly Intelligence Summary: Ep 1

421

Weekly Intelligence Summary: Ep 0

422

Episode 56: Positive cyber security developments for 2019

423

Episode 55: Tackling Phishing

424

Episode 54: Marriott Breach And 2019 Trends

425

Episode 53: Threat Actors Use of Cobalt Strike & How Attacker Actions Can Inform Defenses

426

Episode 52: Black Friday and Cybercrime

427

Episode 51: Phineas Fisher and the Hacking Team Investigation

428

Episode 50: CISCO ASA 0-day and VirtualBox Vulnerability

429

Episode 49: 81,000 Hacked Facebook Accounts For Sale

430

Episode 48: Tesco Bank Fraud And £16.4m FCA Fine

431

Episode 47: Ransomware Surges in October, Cathay Pacific Breach, and Triton Attributed

432

Episode 46: Supply Chain and Third-Party Risks

433

Episode 45: FASTCash Hidden Cobra, MSP Risks, Five Eyes Tooling Report

434

Episode 44: Business Email Compromise

435

Episode 43: Security Flaws Affect 50 Million Facebook Accounts and Equifax Fined £500,000

436

Episode 42: Security Layering and Usability Trade-offs

437

Episode 41: Magecart Payment Card Thefts

438

Episode 40: DoJ Complaint Charges North Korean Actor For Sony Attacks, WannaCry, and More

439

Episode 39: Credential Hygiene

440

Episode 38: Midterm meddling and threat modeling

441

Episode 37: ATM Fraud and Cashout Operations

442

Episode 36: FIN7 Arrests and Phishing Threats

443

Episode 35: Cyber threats to ERP Applications

444

Episode 34: Satori Botnet, OilRig, PowerShell Security, and the Dragonfly Campaign

445

Episode 33: Digital Risk Protection

446

Episode 32: MITRE ATT&CK™ Framework and the Mueller GRU Indictment

447

Episode 31: Carbanak Files and Source Code Leaked?

448

Episode 30: SSL Inspection and Interception: Uses, Abuses and Trade-offs

449

Episode 29: Reducing Your Attack Surface: From a Firehose to a Straw

450

Episode 28: Diversity in Security and Women’s Network Launch

451

Episode 27: Attribution: The How, The What and The Why

452

Episode 26: Mythbusting Vulnerabilities and Exploits

453

Episode 25: Combating Security Debt, Ticketfly Defacement And Data Breach

454

Episode 24: Seize and Desist: Changes in the cybercriminal underground

455

Episode 23: L0pht 20 years on and combating cyber threats with military-style tactics

456

Episode 22: VPN Filter targeting Ukraine, TRITON malware, Roaming Mantis, VBScript & Spectre vulns

457

Episode 21: eFail vulns affecting Open PGP and S-MIME, and interbank payment systems risks

458

Episode 20: Winnti Umbrella, DarkHotel, Office 365 Vulnerability, and Olympus Dark Web Marketplaces

459

Episode 19: Loki Bot, LoJack, GPON Vulnerabilities, and Blackrouter Ransomware

460

Episode 18: Healthcare hacking, BGP hijacking, crypto jacking, and more

461

Episode 17: Network Infrastructure Compromise, Magnitude EK Development, the Gold Galleon, & more

462

Episode 16: Cisco Smart Install Client flaw, Microsoft Outlook vuln, OpIcarus, RSAC, and more

463

Episode 15: 1.5 Billion Files Exposed Through Misconfigured Services

464

Episode 14: Panera Breach Lessons, WannaCry’s Re-emergence, Genesis Marketplace, and more

465

Episode 13: Cambridge Analytica, Trickbot Updates, SamSam Surge Continues, And Dragonfly Attributed

466

Episode 12: Tax Fraud, AMD Vulnerability, Slingshot Targets Mikrotik Routers, And Hermes Ransomware

467

Episode 11: Memcached attacks, disinformation in ME, Spectre exploit, German gov network intrusion

468

Episode 10: Memecached Server DDoS, Flash Vuln in Spam Campaign, Trustico Cert Issues, & Ransomware

469

Episode 9: SWIFT Attacks, Business Email Compromise, Return Of Thedarkoverlord, And APT - 37

470

Episode 8: Lazarus Group, Olympics opening ceremony, Bitgrail Theft, and Outlook vulnerabilities

471

Episode 7: Operation Pzchao, Threats To The Winter Olympics, Infraud Forum Arrests, And More

472

Episode 6: Cryptocurrency Fraud In-Depth

473

Episode 5: $530 Million Cyber Heist, DDoS Against Dutch Banks, And The Future Of Anonymous

474

Episode 4: Dridex, Dark Caracal, Turla, Cozy Bear, And More

475

Episode 3: CVE-2018 -0802, Mirai Okiru, Bancomext Targeted, and Triton Malware

476

Episode 2: CoffeeMiner, Turla, and Cyber Threats to the Winter Olympics

477

Episode 1: Spectre, Meltdown, Satori, and OpNetNeutrality