uk

ReliaQuest

ShadowTalk: Powered by ReliaQuest

News EN ↓ Епізодів: 493

Want to hear what industry experts really think about the cyber threats they face? ShadowTalk is a weekly cybersecurity podcast, made by practitioners for practitioners, featuring analytical insights on the latest cybersecurity news and threat research. Threat Intelligence Analyst John Dilgen brings extensive expertise in cyber threat intelligence and incident response, specializing in researching threats impacting ReliaQuest customers. John and his guests provide practical perspectives on the week’s top cybersecurity news and share knowledge and best practices to help businesses mitigate the...

Обов'язково відвідайте сайт подкасту та підтримайте його автора: reliaquest.com

Автор

ReliaQuest

Категорія

News

Сайт подкасту

reliaquest.com

Останній епізод

30 вер 2026

Де слухати?

Подкасти в застосунку Replaio Radio Уже незабаром

Подкасти незабаром з'являться в застосунку. Встановіть уже зараз і першими побачте зовсім новий погляд на подкасти

Завантажити з Google Play Встановіть безкоштовно Android майже 10 млн завантажень · рейтинг 4,8 iOS незабаром

Епізоди

CISO Wisdom: Turning Security Investments Into Measurable Risk Reduction 30.09.2026

Security teams are contending with more tools, alerts, and vulnerabilities than ever—but volume does not necessarily equal security. Jigar Shah joins us to discuss how organizations can automate repetitive work, prioritize vulnerabilities based on business risk, build identity-driven security strategies, and connect cybersecurity investments to measurable outcomes. With two decades of leadership e...

Fake NDAs, Real Money: Inside the M&A Social Engineering Playbook 23.09.2026

In this episode, we examine the Phantom Deal campaign, in which threat actors used publicly available details about companies’ acquisition histories, subsidiaries, executives, and employees to create convincing fake M&A scenarios. The goal: persuade employees to initiate large financial transfers while keeping conversations off corporate communication channels. We also cover a recent series of...

From Vulnerability Research to Domain Admin in Minutes 16.09.2026

AI is changing the economics of cyberattacks. In this episode, we examine how a suspected threat actor used AI agents to accelerate PaperCut vulnerability research, exploit development, target identification, and post-compromise activity—moving from initial access to domain administrator access in as little as seven minutes. We also explore recent reporting on large-scale AI-model distillation cam...

One Empty Field: The Email Security Bypass Letting Attackers Impersonate Your Executives 09.09.2026

Organizations rely on Microsoft 365's RejectDirectSend control to block internal email spoofing—but a structural gap lets attackers walk right past it. With nothing more than a basic Python script and an empty envelope sender, threat actors are impersonating executives, IT support, and finance teams to launch Business Email Compromise, payment fraud, and follow-on account takeover. Join hosts...

From Data Dumps to Critical Findings: The New Era of Data Extortion 02.09.2026

Threat actors do not see old email archives, forgotten shared drives, and outdated CRM exports as clutter. They see them as searchable inventory. With AI-assisted analysis, attackers can rapidly identify sensitive communications, regulatory exposure, customer relationships, and credentials buried in stolen data. Join hosts John Dilgen and Brandon Tirado as they discuss: Why data theft has become a...

Vishing at Scale: Inside the Criminal SaaS Platform Enabling Account Takeover 26.08.2026

What if a threat actor already knew your name, your job title, your manager's name, and your direct number before they ever picked up the phone? That's not a hypothetical — that's Work Panel. A new report gave us a rare inside look at the criminal SaaS platform enabling vishing campaigns at scale, and the findings are a wake-up call.   Join hosts John Dilgen and Alexandra Moore as t...

Nation-State Actors: Iran’s PLC Attacks, Russia’s Zero-Click Email Exploit, and North Korea’s Fake Employees 19.08.2026

Three nation-states. Three distinct playbooks. Iranian actors are targeting internet-exposed industrial controllers and disabling critical safety systems. A Russian threat group built a zero-click email exploit that steals 90 days of inbox data the moment a user views a message. And North Korean operatives are applying for software-development jobs at Western companies—and getting hired. Join host...

When AI Escapes the Lab: The Hugging Face Breach, PyPI Malware, and What It Means for Defenders 12.08.2026

Fully autonomous attacks are here. AI agents escape a test environment, exploit zero-days, coordinate through shared infrastructure, and breach a production company—generating more than 17,000 security events along the way. Elsewhere, another model autonomously publishes malware to PyPI, while AI agents target real open-source developers with tailored social engineering.  Join hosts John Dilgen an...

The Gentlemen, Deadlock, and Clop: The Groups Driving Ransomware & Extortion in 2026 05.08.2026

An affiliate receives a ready-made intrusion kit — pre-compromised targets, an EDR killer, and a full deployment workflow included. No building from scratch. No long ramp-up. Just deploy, observe, and iterate. That's the future of ransomware; it's how the new number-one group operated in Q2 2026. And it's just one of three stories reshaping the extortion landscape right now. Join ho...

Compromised Hotel Gateways, Fake Microsoft Domains, and the APT28-Adjacent Campaign That Bypasses MFA Without a Phishing Click 29.07.2026

An employee connects to hotel Wi-Fi, receives a familiar Microsoft 365 sign-in prompt, and authenticates. No phishing email. No malicious link. No suspicious attachment. Yet an attacker walks away with a valid, MFA-satisfied session token.  Join hosts Alexandra Moore and John Dilgen as they break down: How compromised hotel and conference-center Wi-Fi gateways silently redirect Microsoft authentic...

The Largest Patch Tuesday Ever: 622 CVEs, a 1,380% Phishing Surge, and the Two-Front War on Initial Access 22.07.2026

Defenders aren't losing ground on one front, they're losing it on two at once. The largest Patch Tuesday in history just dropped alongside a 1,380% surge in phishing, and threat actors aren't waiting for you to catch up. Join hosts Alexandra Moore and John Dilgen as they break down:  How new extortion group Helix and ClickFix are weaponizing identity compromise at scale  Why 622 vul...

FortiBleed, 70,000 Compromised Devices, and the Credential Economy Powering Every Breach 15.07.2026

When a 20-person team using AI, automated tools, and a list of default credentials compromised 70,000 devices across 194 countries they exposed how mature the criminal market behind credential theft has become. Initial access brokers are now packaging pre-validated enterprise access for an average of $113,000, and the window from information stealer infection to ransomware deployment is just seven...

Inside Conti's Leaked Chats: 300,000 Messages, a Criminal Empire, and the Ransomware Playbook Still Running Today 08.07.2026

When 300,000 internal messages from the world's most prolific ransomware gang were leaked, they exposed more then a shadowy underground network, a full company. HR departments. Conti operated with the structure of a mid-sized software firm, and that changes how defenders need to think about the ransomware landscape today. Join host John and special guest Geoff White , journalist and author of...

How Hackers Are Using AI Right Now: Faster Attacks, Smarter Malware, and a New Arms Race 01.07.2026

AI is not replacing threat actors, instead it is making them faster, cheaper, and harder to stop. From AI powered phishing campaigns generating thousands of pages simultaneously, to a newly discovered macOS implant called Gaslight that injects fabricated system error messages into AI powered triage pipelines, the arms race between attackers and defenders is accelerating. The question is not whethe...

Klue, Kali365, OAuth: When the Front Door Is a Trusted Integration 24.06.2026

In the Klue compromises threat actors walked in through a trusted integration, using legitimate credentials to quietly siphon Salesforce CRM data at scale. The challenge isn't just responding to Klue. It's recognizing that every OAuth-connected integration in your environment is part of your attack surface. Join hosts Alexandra and John as they discuss: How compromised Klue integrations...

ShinyHunters' Expanding Toolkit: Oracle PeopleSoft Zero-Day Exploitation and the BreachForums Defense Gaps 17.06.2026

ShinyHunters dominated headlines this week: a zero-day, a BreachForums listing, and unverified claims all hitting at once. The problem isn't just keeping up with the volume. It's knowing which of it is real, which is noise, and what your team actually needs to act on. Join hosts Tehman and John as they discuss: ShinyHunters zero-day exploitation of CVE-2026-35273 Why a BreachForums listi...

China-Linked Cyber Espionage: How OP-512 Exploited Legacy IIS Servers and Evaded Detection 10.06.2026

Your team built defenses around known China-linked clusters. The file hashes are tracked. The behavioral patterns are documented. What those weren't built to catch is a new cluster that studied those exact defenses and engineered around them. A China-linked attacker compromised an internet-facing IIS server, maintained access for over 75 days, and came back on fresh infrastructure. With four...

SonicWall, MFA Bypass, IABs: Why Patched Devices Are Still Handing Attackers Initial Access 03.06.2026

Your team patches the device. The firmware version matches the advisory. The ticket closes. The device comes off the remediation queue. What your workflow never tracked is that the advisory also required six manual LDAP configuration steps — and without them, the authentication bypass still works. An initial access broker authenticated through the VPN, reached a domain-joined file server, and was...

Device Code, OAuth, PhaaS: How Session Token Theft is Breaking the Phishing Playbook 27.05.2026

Your user clicked a link, landed on a real Microsoft login page, typed their password, completed MFA, and walked away thinking nothing happened. Somewhere across the internet, an attacker's device just received an authenticated session token. The password is irrelevant. The MFA prompt already fired and passed. With PhaaS platforms now converging on token-theft tradecraft and post-compromise a...

SQLite, Mistral, OpenAI: How AI Attacks Are Reshaping the Attack Surface 20.05.2026

What happens when an AI agent uncovers a zero-day in hours instead of weeks, and state-backed groups are already operationalizing the same tools? With self-hosted AI infrastructure sprawling outside asset registers and supply chain worms reaching inside AI vendors themselves, defenders need a new operating model. Join hosts Tehman and John as they discuss:  How an AI agent surfaced a memory-safety...

Canvas, Trellix, Mini Shai-Hulud: How Defenders Respond When Supply Chain Attacks Become Weekly 14.05.2026

What's driving the surge in weekly supply chain attacks, and why does the real defender problem start after the supplier gets hit? With 275 million records exposed and 8,809 institutions caught in the downstream fallout, organizations need a new playbook. Join hosts Alexandra and John as they discuss: How ShinyHunters abused admin sessions RansomHouse's hypervisor-focused automation How...

Akira, ShinyHunters, and The Gentlemen: Extortion Lessons From Early 2026 06.05.2026

What factors have driven the top ransomware and extortion groups' success in early 2026? And how should organizations structure their defenses to protect against them? Join hosts Alexandra and John as they discuss: How Akira is exploiting unknown assets inherited through M&A Why ShinyHunters' vishing and SaaS misconfiguration models work How The Gentlemen grew 588% quarter-over-quart...

What Happened to Black Basta's Playbook? The Automated Teams Phishing Threat Hitting Executives 29.04.2026

Black Basta disbanded in February 2025, but their playbook didn't go with them. In March 2026, 77% of observed incidents targeted executives and directors, and attackers moved from first contact to malicious script execution in as little as 12 minutes. The tactic has been automated, refined, and is now running faster than most SOCs can respond.  Join hosts Alexandra and John as they discuss:...

Did ShinyHunters Compromise Vercel? Every CISO's Cloud Security Visibility Problem 22.04.2026

89% of organizations that suffered a SaaS breach last year believed they had appropriate visibility. They had the logs — what they lacked was detection on what mattered. The Vercel incident shows exactly how costly that gap can be.  Join hosts Brandon and John as they discuss: How a third-party OAuth chain may have exposed Vercel's internal data Why SaaS visibility gaps leave organizations ex...

What Claude Mythos Means for Organizations 15.04.2026

Resources: https://linktr.ee/ReliaQuestShadowTalk Join hosts John and Alex, alongside special guest and ReliaQuest CTO Joe Partlow, as they discuss: How Claude Mythos autonomously generated exploits Why AI is accelerating CVE volume Defense strategies organizations need now Joe Partlow: CTO of ReliaQuest, a leading Information Security provider and is currently involved with new product initiative...

Слухайте подкаст ShadowTalk: Powered by ReliaQuest у Replaio

Радіо та подкасти в одному застосунку - безкоштовно й без реєстрації. Встановіть уже сьогодні та не пропустіть запуск

Завантажити з Google Play

Replaio не є видавцем подкастів; назви шоу, обкладинки та аудіо належать їхнім авторам і поширюються через публічні RSS-канали