Threat Talks

Threat Talks - Your Gateway to Cybersecurity Insights

News EN ↓ 130 episodes

Threat Talks is your cybersecurity knowledge hub. Unpack the latest threats and explore industry trends with top experts as they break down the complexities of cyber threats. We make complex cybersecurity topics accessible and engaging for everyone, from IT professionals to every day internet users by providing in-depth and first-hand experiences from leading cybersecurity professionals. Join us for monthly deep dives into the dynamic world of cybersecurity, so you can stay informed, and stay secure!

Author

Threat Talks

Category

News

Podcast website

threat-talks.com

Latest episode

Jul 7, 2026

Where to listen?

Podcasts in the app Replaio Radio Coming soon

Podcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts

Get it on Google Play Install for free Android 5M+ downloads · 4.8 rating iOS soon

Episodes

Maritime Cybersecurity: Predictable = Hackable 13.01.2026

You’re Port Control. A vessel requests entry. No captain. No crew. Just autonomy. In maritime cybersecurity, the risk isn’t that the ship is autonomous. It’s that you no longer know who’s steering. Lieuwe Jan Koning (Co-Founder & CTO, ON2IT) joins Stephen McCombie (Professor of Maritime IT Security, NHL Stenden) and Hans Quivooij (CISO, Damen Shipyards) to expose the illusion of control in aut...

Before the Mayday: Cyber ​​Attacks at Sea 06.01.2026

Could Stuxnet happen again - this time at sea? In this Threat Talks episode, host Lieuwe Jan Koning sits down with Professor Stephen McCombie, global expert in maritime cybersecurity, to unpack real-world cyber attacks on critical infrastructure and why the maritime sector is dangerously exposed. From GPS spoofing and insider threats to aging ship systems and state-sponsored attacks, this conversa...

Looking Back at 2025: Cybersecurity at a Turning Point 30.12.2025

2025 was the year detection stopped being enough. Because attacks stopped behaving the way detection was built to handle. OT systems were hit with real-world consequences. AI stopped being just a productivity tool and became an attacker. And SOCs discovered - often painfully - that speed alone still means reacting too late. In this special end-of-year Threat Talks episode, Lieuwe Jan Koning is joi...

BGP Vortex: Internet Kill Switch? 23.12.2025

Could a single BGP trick really break the internet? A new “BGP Vortex” claim says yes  - by abusing route oscillation and BGP communities to trigger endless update loops and exhaust router CPU. So we check what actually holds up in the real world. In this Threat Talks Deep Dive, Rob Maas, Field CTO at ON2IT, sits down with Eric Nghia Nguyen Duy, Network Engineer at AMS-IX, to understand what BGP (...

WSUS RCE: Update Weaponized 16.12.2025

Attackers are abusing a WSUS flaw - Microsoft’s Windows Server Update Services - to detonate PowerCat, spawn reverse shells, and plant ShadowPad. All from the update server your entire Windows estate trusts by default. One weak crypto key and a broken deserialization function let attackers hit your WSUS server with unauthenticated SYSTEM-level code execution. Chinese APT groups are already exploit...

Bad Successor: The Service Account Flaw to Watch 09.12.2025

It was built to secure service accounts. Instead, it became the cleanest privilege-escalation vector of 2025. They called it Bad Successor (A.K.A. CVE-2025-53779). A new “secure by design” feature in Windows Server 2025 -DMSA -was supposed to fix service account hygiene. Instead, it introduced a loophole where attackers could claim successor status, skip password requirements, and silently inherit...

From Hacker to Hero 03.12.2025

What if your next great cyber defender is a teenager gaming in their bedroom right now? In this Threat Talks episode, Lieuwe Jan Koning and former FBI Supervisory Special Agent William McKean (founder of The Redirect Project) explore how young digital natives go From Hacker to Hero. They chart the journey from gaming and online communities to risky first hacks and real-world intrusions. Then they...

The Npm Worm Outbreak 25.11.2025

The world’s biggest open-source ecosystem - npm - faced its first self-spreading worm. They called it Shai Hulud. It didn’t just infect one package. It infected developers themselves. When a maintainer got phished, the worm harvested credentials, hijacked tokens, and created new CI/CD workflows to keep spreading - automatically . No command-and-control. No manual uploads. Just a chain reaction acr...

Inside the SalesLoft Breach 18.11.2025

You were promised safe SaaS - but got silent data loss. In Inside the Salesloft Breach, Rob Maas and Luca Cipriano expose how trusted integrations became the attack vector. They trace how vishing calls, trojanized Salesforce tools, and GitHub-to-AWS pivots gave attackers OAuth access and drained CRMs without a single alert. You’ll hear how Drift integrations and bulk SOQL queries quietly moved dat...

The App Store Nightmare: Why AI MCP Stores Are a Trap 11.11.2025

The new AI app store is here - and it’s already making choices for your company. This episode shows you how to spot it, stop it, and stay safe. Host Lieuwe Jan Koning with RobMaas (Field CTO, ON2IT) explain the app store nightmare in plain language. A new system (MCP) lets AI tools like ChatGPT , Claude , and Gemini do tasks for you - sometimes too much. When a bad tool or a sneaky document gets i...

The Secret Diplomats Fighting Cyber Wars 04.11.2025

Cyber defense doesn’t just happen in code. It’s shaped in conversation. Behind every cyber norm or sanction, there’s a diplomat working to stop digital wars before they start.   In this episode of Threat Talks, Lieuwe Jan Koning (CTO & co-founder of ON2IT) sits down with Ernst Noorman, Ambassador at Large for Cyber Affairs for the Kingdom of the Netherlands. They reveal how backchannel talks,...

Patch Smarter, Not Harder 28.10.2025

Patch smarter, not harder. Lieuwe Jan Koning and ON2IT Field CTO Rob Maas break down why “patch everything now” isn’t a strategy, but a risk multiplier. In this session, they teach a practical patching strategy : know your assets, patch edge first, stage updates, and use Zero Trust segmentation to choke off exposure so you only patch what truly matters: fast, safely, and without outages. (00:00) -...

Public Key Infrastructure: The Foundation of Digital Trust 21.10.2025

How solid is your digital trust—or are you just hoping your PKI is secure? Let’s be honest: too many companies run on borrowed trust and forgotten certificates. In this episode of Threat Talks, ON2IT’s Lieuwe Jan Koning and Rob Maas pull back the curtain on what really holds your digital world together—and what can tear it down overnight. They break down PKI in plain language: the root of trust th...

Why Your Cyber Hygiene Matters? 14.10.2025

One unlocked phone can unravel the defenses of a billion-dollar enterprise—because in cybersecurity, small mistakes don’t stay small for long. Attackers can read notes, steal IDs, or impersonate you on WhatsApp. A reused password can launch a remote tool that looks completely legitimate. Rob Maas (Field CTO, ON2IT) and Luca Cipriano (Cyber Threat Intelligence Program Lead, ON2IT) reveal how poor c...

Resilience Over Fragmentation: The Risk You Can’t Ignore 07.10.2025

The internet promised freedom. Now it monetizes you. The trade-off? Convenience for control. In this episode, Lieuwe Jan Koning and Prof. Jacobs reveal how scattered tools like meta and X create security gaps—and how one policy, fewer interfaces, and less data shared cut exposure and keep operations running. Real examples you’ll hear: • The neighborhood chat stuck on WhatsApp—and how switching to...

Zero Trust Step 5B: Maintain Controls 30.09.2025

Boards don’t buy dashboards—they buy assurance. Breaches are late-stage symptoms of drift: rules pile up, logs lose signal, cloud/Kubernetes outpace governance. Lieuwe Jan Koning (ON2IT Co-Founder) and Rob Maas (Field CTO) show how Zero Trust Step 5B (Maintain) proves your controls still work—today. (00:00) - — Welcome & Zero Trust Step 5B (00:57) - — Five steps: fast recap (03:12) - — Maintai...

Defend Against Hacktivist Groups like APT Handala | The Cyber Security Podcast 23.09.2025

Hacktivists don’t need zero-days to hurt you—they weaponize people. Host Lieuwe Jan Koning sits down with Yuri Wit (SOC analyst) and Rob Maas (Field CTO) to dissect APT Handala: how they hunt targets, deliver wipers, and brag about leaks. We map their moves to the Lockheed Martin Kill Chain and turn it into a Zero Trust defense playbook you can actually use—today. (00:00) - - 01:40 - Introduction...

Promptlock – The First AI-Powered Malware | The Cyber Security Podcast 16.09.2025

First documented case: AI inside the breach. Promptlock marks the first time malware has used AI during execution, not just in preparation. In this Threat Talks deep dive, Rob Maas (Field CTO, ON2IT) sits down with Yuri Wit (SOC Analyst, ON2IT) to break down how it works: a Go loader calling an attacker’s LLM in real time, generating fresh payloads that adapt on the fly. This episode strips away s...

Data Bouncing: How HTTP Headers Leak Data | The Cyber Security Podcast 09.09.2025

Your tools say “secure.” Your headers say “leaking.” In this Threat Talks Deep Dive, ON2IT’s Luca Cipriano (CTI & Red Team Lead) exposes Data Bouncing—a stealthy exfiltration trick that hides inside HTTP headers and abuses DNS lookups through trusted third parties. We show the demo, decode the psychology of the attack, and translate it into Zero Trust moves you can deploy today. (00:00) - – Wh...

AI, Play It Safe: Why CISOs Are Wrong to Ban AI 02.09.2025

Playing it safe with AI sounds smart, but is banning it really how you prevent data leaks? In this episode of Threat Talks, ON2IT’s Lieuwe Jan Koning (ON2IT Co-Founder) sits down with Rob Maas, Field CTO at ON2IT, to tackle the hard question: How can CISOs and security leaders embrace AI safely—without exposing their organization to destructive data leaks? From Samsung’s ChatGPT ban to real-world...

Zero Trust step 5A: Stop Breaches—Inspect Every Event Now | The Cybersecurity Podcast 26.08.2025

Zero Trust step 5A is where monitoring turns raw logs into decisive action. Hosts Lieuwe Jan Koning and Rob Maas (Field CTO, ON2IT) expose why MDR alone isn’t protection—and how context closes the gap. Learn to inspect every event, use Indicators of Good/Compromise, and set Rules of Engagement that stop lateral movement and alert fatigue. (00:00) - — Welcome & Step 5A (Monitor) setup (00:37) -...

From Stealth to Wipers: Inside Russia’s APT 44 AKA Seashell Blizzard | The Cybersecurity Podcast 19.08.2025

Russia’s most notorious cyber unit—Seashell Blizzard (also known as Sandworm, APT 44 and Iron Viking)—has taken down shipping giants, Olympic systems, and Ukraine’s power grid. In this Threat Talks deep dive, Lieuwe Jan Koning, Yuri Wit (Red Team), and Rob Maas (Blue Team) reveal exactly how these attacks unfold, why they’re so hard to stop, and how Zero Trust can tip the balance back to defenders...

Signal Gate: One Wrong Number Triggered the Largest U.S. Gov Data Leak | The Cybersecurity Podcast 12.08.2025

One mis-typed contact detonates Signal Gate, turning “secure” messaging into a classified-data leak. Host Lieuwe Jan Koning (Co-founder, ON2IT) and Thomas Manolis (Security Officer, AMS-IX) lay out the breach blow-by-blow—then drop the Zero Trust, Shadow IT and information-governance tactics every CISO needs before the next incident hits. High stakes, hard lessons—compressed into actionable steps...

Splinternet Reality Check: Zero Trust Strategies for a Fragmenting Web 06.08.2025

ON2IT’s Lieuwe Jan Koning goes one-on-one with AMS-IX CEO Peter van Burgel to expose why the once-open internet is splintering into rival, firewalled regions. Discover the geopolitical forces fueling this cybersecurity trend. Learn the Zero Trust resilience moves CISOs must deploy to stay sovereign in the future of the internet. Key Topics Covered • Drivers behind the Splinternet & what they m...

Zero Trust Step 4B: How to Secure Admin Access 29.07.2025

Administrative accounts come with serious power – and serious power, comes with serious risk. In part B of our deep dive into step four of Zero Trust (create Zero Trust policy), host Lieuwe Jan Koning and ON2IT Field CTO Rob Maas unpack how to build Zero Trust policies specifically for administrative access.  They explore: 1) Why admins are a high-value target – and what that means for policy 2) H...

Listen to the Threat Talks - Your Gateway to Cybersecurity Insights podcast in Replaio

Radio and podcasts in one app - free, with no sign-up. Install today and do not miss the launch

Get it on Google Play

Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.