Retour

Explorez tous les épisodes du podcast ShadowTalk: Powered by ReliaQuest

Plongez dans la liste complète des épisodes de ShadowTalk: Powered by ReliaQuest. Chaque épisode est catalogué accompagné de descriptions détaillées, ce qui facilite la recherche et l'exploration de sujets spécifiques. Suivez tous les épisodes de votre podcast préféré et ne manquez aucun contenu pertinent.

Rows per page:

1–50 of 474

TitreDateDurée
Why Cloud Threats Are Escalating: Identity Risks, Automation Flaws, and Legacy Vulnerabilities, Plus the Latest on Chinese APT Campaigns and NPM Package Abuse05 Nov 202500:27:18

Resources: https://linktr.ee/ReliaQuestShadowTalk

Did you know 99% of cloud identities are over-privileged, creating the perfect storm for attackers to seamlessly infiltrate your environment? Join host Kim along with intelligence analysts John & Alex as they discuss: 

  • Chinese Nation-State Campaigns and Geopolitics (1:12)
  • Malicious NPM Packages (7:20)
  • TruffleNet Attacks on AWS (10:53)
  • The Danger of Over-Privileged Cloud Identities (15:36)

Kim Bromley: Senior Cyber Threat Intelligence Analyst on the ReliaQuest Threat Research Team. She joined ReliaQuest in June 2020 following a 10-year career in UK law enforcement, and has acted as host since 2024.  Kim brings a wealth of experience in threat intelligence and law enforcement tactics, providing unique insights.

John Dilgen: Cyber Threat Intelligence Analyst at ReliaQuest, where he specializes in researching cyber threats impacting ReliaQuest customers. With a strong technical background, he previously served as an Incident Response Analyst and Trainer at ReliaQuest.

Alexander Capraro: Alexander Capraro is a Cyber Threat Intelligence Analyst at ReliaQuest with over five years of experience in cybersecurity. With his prior experience as a Security Analyst, he specializes in incident response, malware campaign tracking, and OSINT investigations. 

 

Why Cyber Threats Surge 20% During M&A, Plus the Latest on Qilin and Lazarus Group Campaigns29 Oct 202500:31:05

Resources: https://linktr.ee/ReliaQuestShadowTalk

Picture this: You close a $50M acquisition on Friday and by Monday, attackers are in your network. Sound far-fetched? It's not. Join host Kim along with intelligence analyst John & Threat Hunter Leo as they discuss:

  • Attackers Exploit WSUS Flaw (1:15)
  • Qilin Deploys Cross-Platform Attacks (4:21)
  • Lazarus Group Reignites Operation DreamJob (9:05)
  • Threat Hunter Hacks: Active Cyber Threats in M&A (15:19)

Kim Bromley: Senior Cyber Threat Intelligence Analyst on the ReliaQuest Threat Research Team. She joined ReliaQuest in June 2020 following a 10-year career in UK law enforcement, and has acted as host since 2024.  Kim brings a wealth of experience in threat intelligence and law enforcement tactics, providing unique insights.

John Dilgen: Cyber Threat Intelligence Analyst at ReliaQuest, where he specializes in researching cyber threats impacting ReliaQuest customers. With a strong technical background, he previously served as an Incident Response Analyst and Trainer at ReliaQuest.

Leo Dawson: Leo Dawson is a Threat Hunter on the ReliaQuest Threat Research Team. With a deep background in Experimental Physics and Artificial Intelligence, Leo brings a unique interdisciplinary perspective to cybersecurity. He is driven by a passion for leveraging these skills to proactively track, analyze, and understand threat actor campaigns while gaining deeper insights into their evolving tactics and behaviors. 

New Silk Typhoon Attacks, the Cybercriminal Recruitment Underworld, and More!27 Aug 202500:26:26

Resources: https://linktr.ee/ReliaQuestShadowTalk

Curious about the skills needed for modern cyber attacks? Join host Kim along with intelligence analysts John & Hayden as they discuss:

  • Apple Patches Exploited Zero-Day (1:40)
  • Hackers Abuse Linux Files to Drop Malware (3:50)
  • Silk Typhoon Attacks Cloud Supply Chains (7:21)
  • ReliaQuest Uncovers Cybercriminals' Most Sought After Skills (11:02)

Kim Bromley: Senior Cyber Threat Intelligence Analyst on the ReliaQuest Threat Research Team. She joined ReliaQuest in June 2020 following a 10-year career in UK law enforcement, and has acted as host since 2024.  Kim brings a wealth of experience in threat intelligence and law enforcement tactics, providing unique insights.

John Dilgen: Cyber Threat Intelligence Analyst at ReliaQuest, where he specializes in researching cyber threats impacting ReliaQuest customers. With a strong technical background, he previously served as an Incident Response Analyst and Trainer at ReliaQuest. 

Hayden Evans: Cyber Threat Intelligence Analyst at ReliaQuest. He has experience in the F3EAD lifecycle and analyzing adversaries' TTPs to operationalize this information. He is also experienced with intrusion response, OSINT investigations, and offensive security. 

Weekly: Apache ActiveMQ and Atlassian Confluence, SEC files charges, QR code phishing08 Nov 202300:35:50

In this episode of ShadowTalk, host Ivan Righi, along with ReliaQuest's CISO Rick Holland and Detection Researcher Marken Teder, discuss the latest news in cyber security and threat research. Topics this week include:

  • Apache ActiveMQ vulnerability (CVE-2023-46604) exploited by ransomware gangs
  • Discussion over charges filed by the US SEC against SolarWinds
  • Active exploitation of a Critical Atlassian Confluence flaw (CVE-2023-22518)
  • An overview of QR code phishing threats

Resources:

Weekly: SolarWinds SEC Charges, Vulnerabilities Roundup, AI Executive Order02 Nov 202300:33:23

In this episode of ShadowTalk, host Kim, along with Caroline and Corey, discuss the latest news in cyber security and threat research. Topics this week include:

  • The charges filed by the US SEC against SolarWinds
  • A sneak-peak of the findings from our Vulnerabilities Roundup blog
  • An overview of some vulnerabilities impacting users right now
  • The Executive Order issued by the Biden administration on artificial intelligence.


Weekly: Q3 Ransomware Report, ServiceNow Vulnerability, Okta Incident26 Oct 202300:35:16

In this episode of ShadowTalk, Host Chris Morgan is joined by one of ReliaQuest's CISO's Rick Holland, Threat Hunter Brian Kelly and Threat Intelligence Analyst Ivan Righi to discuss the latest news in cyber security and threat research. Topics this week include:

  • The findings of ReliaQuest's Quarterly Ransomware Report recapping Q3 2023 activity.
  •  ServiceNow vulnerability and what it means for you
  • The latest on a security incident pertaining to authentication provider, Okta.

Resources:



Weekly: Critical CISCO IOS XE Vuln, Business Email Compromise (BEC) activity, malicious use of Discord20 Oct 202300:43:33

In this episode of ShadowTalk, host Chris, along with Kim and Gjergji, discuss the latest news in cyber security and threat research. Topics this week include:

  • Threat actors exploiting Critical CISCO IOS XE Vuln 
  • Increase in Business Email Compromise (BEC) activity
  • Social media platform Discord being used for malicious activity
Weekly: Hamas Cyber Threat Implications, Top Adversary Techniques, Qakbot13 Oct 202300:36:12

In this episode of ShadowTalk, host Chris Morgan, along with ReliaQuest CISO Rick Holland, James Xiang and Caroline Fenstermacher, discuss the latest news in cyber security and threat research. Topics this week include:

  • Cyber threat implications from the Hamas - Israel Conflict
  • Top Adversary Techniques: What We're Seeing Right Now
  • Has Qakbot returned? 

Resources:

Weekly: National Cyber Security Awareness Month (NCSAM), Progress FTP Server, RDP Sessions, IronNet06 Oct 202300:36:45

In this episode of ShadowTalk, host Chris Morgan, along with ReliaQuest CISO Rick Holland and Corey Carter discuss the latest news in cyber security and threat research. Topics this week include:

  • 2023 National Cyber Security Awareness Month (NCSAM) 
  • Progress FTP Server
  • The risk posed by open Remote Desktop Protocol (RDP) Sessions
  • IronNet ceasure operations

Resources:

Weekly: Hunting for MFA bypass techniques, Libwebp Vuln exploited, VMWare ESXi 29 Sep 202300:29:42

In this episode of ShadowTalk, host Chris, along with Gjergji and James, discuss the latest news in cyber security and threat research. Topics this week include:

  • Hunting for MFA bypass techniques
  • Exploitation of a Zero-day LibWebP Vulnerability
  • Threat actors targeting VMWare ESXI

Resources:

https://www.reliaquest.com/blog/mfa-bypass-techniques/#:~:text=Attackers%20also%20bypass%20MFA%20by,for%20sale%20on%20cybercriminal%20platforms. 

Weekly: MFA Bypass Techniques, Microsoft Data Leak, Latest ALPHV Attack22 Sep 202300:27:26

In this episode of ShadowTalk, host Kim, along with Caroline and Brian, discuss the latest news in cyber security and threat research. Topics this week include:

  • A deep dive into popular MFA bypass techniques and how to mitigate them
  • How a misconfigured SAS token led to a big Microsoft data breach
  • The latest ALPHV ransomware attack

Resources:

Weekly: Anonymous Sudan, Domain Redirection Attacks, UK Ransomware Report and Managed Engine Zero-Day Exploit14 Sep 202300:34:41

In this episode of ShadowTalk, host and ReliaQuest CISO Rick Holand and ReliaQuest Threat Research team members Corey Carter and Gjergji Paco discuss the latest news in cyber security and threat research. Topics this week include:

  •  A deep dive on domain redirection attacks
  • New ransomware report from the UK government
  • New Managed Engine zero-day exploited by multiple threat actors
  • Anonymous Sudan Telegram bans and DDoS attacks.

Resources:

Weekly: SocGhoulish deep dive, AI security concerns, LockBit vs. UK MOD08 Sep 202300:34:24

In this episode of ShadowTalk, host Roman, along with Corey and Ivan, discuss the latest news in cyber security and threat research. Topics this week include:

  • A deep dive of malware loader SocGhoulish
  • Artificial intelligence: implications, security concerns, and use by cybercriminals
  • LockBit leaking top secret information from the UK’s Ministry of Defence

Resources: 

Warlock Ransomware Hits Telecoms, LLM Data Theft, and ShinyHunters Updates20 Aug 202500:25:20

Resources: https://linktr.ee/ReliaQuestShadowTalk

Intrigued by Warlock ransomware's Chinese connection? Join host Kim along with intelligence analysts Joey & John as they discuss:

  • \Warlock Ransomware Attacks Against Telecoms (3:12)
  • New FortiSIEM Flaw Exploited in the Wild (5:19)
  • Man-in-the-Prompt Attack Steals Data from LLMs (8:04)
  • How ReliaQuest Tracks Ransomware Groups and Evolving Cyber Threats (12:36)

Kim Bromley: Senior Cyber Threat Intelligence Analyst on the ReliaQuest Threat Research Team. She joined ReliaQuest in June 2020 following a 10-year career in UK law enforcement, and has acted as host since 2024.  Kim brings a wealth of experience in threat intelligence and law enforcement tactics, providing unique insights.

Joseph Keyes: Cyber Threat Intelligence Analyst at ReliaQuest, specializing in technical cyber threat research. With his prior role as a Cyber Security Analyst, he has gained years of experience in triaging and responding to active threats using GreyMatter's various tools. Joseph is skilled in intrusion response, threat actor profiling, OSINT across the clear and dark web, and analyzing adversarial TTPs. 

John Dilgen: Cyber Threat Intelligence Analyst at ReliaQuest, where he specializes in researching cyber threats impacting ReliaQuest customers. With a strong technical background, he previously served as an Incident Response Analyst and Trainer at ReliaQuest. 

Weekly: Qakbot Takedown, New Barracuda Zero-Day, Resurgence of Hacktivism01 Sep 202300:39:52

In this episode of ShadowTalk, host Chris Morgan, along with ReliaQuest CISO Rick Holland and Gjergji Paco, discuss the latest news in cyber security and threat research. Topics this week include:

  • The FBI operation targeting Qakbot infrastructure
  • Barracuda Zero-Day targeted by Peoples Republic of China (PRC) aligned actors
  • The resurgence and future of Hacktivism
Weekly: Malware Loaders, Ransomware Runbooks, Generative AI and Barracuda ESG25 Aug 202300:28:18
Weekly: DefCon, Cl0p, Raccoon Stealer18 Aug 202300:32:29

In this episode of ShadowTalk, host Chris, along with one of Brandon and Gjergji, discuss the latest news in cyber security and threat research. Topics this week include:

  • Recap of DefCon conference
  • The latest updates regarding Clop's exploitation of MOVEit zero-day
  • The return of the infamous Raccoon Stealer
Weekly: AI at BlackHat, Device Code Phishing, Russia-Ukraine War Trends and DEF CON Tips11 Aug 202300:32:58

In this episode, one of ReliaQuest's CISO's Rick Holland is joined by threat hunters Colin Ferris and Caroline Fenstermacher to discuss the presence of AI at BlackHat, Device Code Phishing, trends from the Russia-Ukraine War and lastly how to make the most of a visit to DEF CON.

Special: CISO Chat Live from BlackHat 202310 Aug 202300:14:32

In this episode, one of ReliaQuest's CISO's Rick Holland and Chief Technology Officer Joe Partlow are joined by Freeport LNG CISO, Todd Beebe and Ciena CISO Ryan Hammer to discuss all things BlackHat 2023.

Weekly: Business Email Compromise (BEC), ReliaQuest Bi-Annual threat reports, influence of AI on the Cyber Threat Landscape04 Aug 202300:40:15

 In this episode of ShadowTalk, host Chris, along with one of ReliaQuest's CISOs Rick, and James, discuss the latest news in cyber security and threat research. Topics this week include:

  • Themes in recent Business Email Compromise (BEC) activity
  • A breakdown of ReliaQuest research into threats facing the Professional, Scientific, and Technical Services (PSTS) sector
  • The influence of AI on the cyber threat landscape 
  • ReliaQuest activities at BlackHat 2023 conference
Weekly: What We're Seeing Right Now, Cl0p Cycle Continues, Ivanti Zero-Day, ALPHV API28 Jul 202300:30:34

In this episode of ShadowTalk, host Roman, along with Ivan and Brandon, discuss the latest news in cyber security and threat research. Topics this week include:

  • Twitter becoming X security concerns
  • Cl0p names 71 new victims
  • ReliaQuest releases Q2 ransomware report
  • Hackers target Norwegian government ministries with Ivanti zero-day exploit
  • ALPHV ransomware group creates API key for its data leak site

Resources:

Weekly: What We're Seeing Right Now, Cl0p Update, WormGPT21 Jul 202300:21:35

In this episode of ShadowTalk, host Chris, along with Brian and James, discuss the latest news in cyber security and threat research. Topics this week include:

  • ReliaQuest research into common attacker techniques
  • An update on Clop's exploitation of the MOVEit vulnerability 
  • ChatGPT rival with ‘no ethical boundaries’ sold on dark web

Resources:

Weekly: Microsoft Cloud Breach, Strava App, Cl0p Update and Remote Management Monitoring14 Jul 202300:38:40
Weekly: Defense Evasion via Virtualization, LockBit target TSMC, CISA Identify New Exploited Vulnerabilities07 Jul 202300:33:08

In this episode of ShadowTalk, host Chris Morgan, along with Corey Carter, Jonny Elrod, Gjergji Paco, and one of ReliaQuests CISO's Rick Holland, discuss the latest news in cyber security and threat research. Topics this week include:

  • Threat actors obfuscating activity through virtualization
  • LockBit claim to have impacted Taiwanese semiconductor giant TSMC
  • CISA identify new exploited vulnerabilities
  • New critical vulnerability impacting Fortinet, FortiOS and FortiProxy SSL-VPN appliances

Resources:

ShinyHunters, Scattered Spider, and Salesforce? Plus, Kimsuky Data Breach!13 Aug 202500:28:04

Resources: https://linktr.ee/ReliaQuestShadowTalk

Want to know if ShinyHunters and Scattered Spider are really working together? Join host Kim along with detection engineer Marken as they discuss:

  • WinRAR Zero-Day Exploited in RomCom Attacks (1:44)
  • New EDR Killer Popular with Ransomware Groups (4:30)
  • Data Breach Reveal Kimsuky Inner Workings (11:31)
  • ReliaQuest Uncovers Potential ShinyHunters x Scattered Spider Collaboration (15:00)

Kim Bromley: Senior Cyber Threat Intelligence Analyst on the ReliaQuest Threat Research Team. She joined ReliaQuest in June 2020 following a 10-year career in UK law enforcement, and has acted as host since 2024.  Kim brings a wealth of experience in threat intelligence and law enforcement tactics, providing unique insights.

Marken Teder: Threat Detection Engineer at ReliaQuest, with a total of 7 years at the company. A native Estonian, he has previously worked as an Incident Response Analyst, Content Developer, and Security Architect. Marken's extensive experience in detection and response brings a robust technical perspective to discussions.

Weekly: Legal Developments, New APT29 Campaign and ReliaQuest's Annual Threat Report 30 Jun 202300:28:27

In this episode of ShadowTalk, host Stefano, along with Kim Bromley, and one of ReliaQuests CISO's Rick Holland, discuss the latest news in cyber security and threat research. Topics this week include:

  • The SEC reportedly charging SolarWinds executives
  • APT29 hunting for credentials
  • Our new, shiny Annual Threat Report

Resources:

Weekly: Cl0p update, Killnet target European financial institutions, closed sources findings23 Jun 202300:42:13

In this episode of ShadowTalk, host Chris, along with Dani, and one of ReliaQuests CISO's Rick Holland, discuss the latest news in cyber security and threat research. Topics this week include:

  • The latest updates related to Cl0p's exploitation of MOVEit zero-day
  • Killnet targeting European financial institutions
  • Insights drawn from our closed sources team
  • The team's observations on this years InfoSec conference

Resources:

Weekly: Cl0p releases company names, Gootloader, new Fortinet RCE, Ukrainians hackers take down Infotel.19 Jun 202300:32:34

In this episode of ShadowTalk, host Chris, along with Colin and Caroline, discuss the latest news in cyber security and threat research. Topics this week include:

  • The latest updates related to Clop's exploitation of MOVEit zero-day
  • An overview of the Gootloader initial access malware
  • Fortinet RCE CVE-2023-27997
  • Ukraine's Cyber Anarchy Squad take down Infotel

Resources:

Weekly: MOVEit Zero-day and Cl0p attribution, Infostealing ecosystem, DBIR 2023 Report09 Jun 202300:32:27

In this episode of ShadowTalk, host Stefano, along with Rick, Dean, and Ivan, discuss the latest news in cyber security and threat research. Topics this week include:

  • What you need to know on the MOVEit Zero-day vulnerability and the latest Cl0p updates 
  • Infostealers ecosystem: most common malware, impact, and mitigation strategies
  • Key insights from the latest Verizon's DBIR issue

Resources:

Weekly: MOVEit Zero-day, RaidForums Breach, Buhti Ransomware02 Jun 202300:18:26

In this episode of ShadowTalk, host Chris, along with Gjergji and Ivan, discuss the latest news in cyber security and threat research. Topics this week include:

  • What you need to know on the MOVEit Zero-day vulnerability
  • RaidForums user's data breached
  • The Buhti ransomware taking a unique approach to targeting victims

Resources:

Weekly: GootLoader, Intrusion Truth, Volt Typhoon, and Exponent conference debrief 26 May 202300:29:55

Summary: In this episode of ShadowTalk, host Stefano, along with Kim, Rick, and Dean, discuss the latest news in cyber security and threat research. Topics this week include:

  • An investigation into the GootLoader malware
  • The latest operation from hacktivist group Intrusion Truth
  • A cyber espionage campaign conduct by Volt Typhoon
  • RQ Exponent conference debrief

Resources:

Weekly: SocGholish, Cactus Ransomware, Greatness Phishing-as-a-service19 May 202300:30:35

In this episode of ShadowTalk, host Chris Morgan , along with Caroline Fenstermacher and Gjergji Paco, discuss the latest news in cyber security and threat research. Topics this week include:

  • Revisiting the SocGholish malware distribution framework 
  • Getting pricked by the Cactus ransomware
  • Greatness Phishing-as-a-service 

Resources:

Weekly: Snake malware takedown, Kubernetes hunts, and Caffeine Phishing-as-a-Service12 May 202300:36:32

Summary: In this episode of ShadowTalk, host Stefano, along with Caroline and Colin, discuss the latest news in cyber security and threat research. Topics this week include:

  • Five Eyes agencies takedown FSB-linked Snake malware
  • Hunting Kubernetes for privilege escalation techniques
  • Investigation offers insights into Caffeine PhaaS platform

Resources:

Weekly: ReliaQuest Threat Management, ALPHV, Veeam Vulnerability Exploited05 May 202300:25:39

In this episode of ShadowTalk, host Chris Morgan is joined by Corey Carter and Ivan Righi to discuss:

  • A day in the life of a Threat Engineer at ReliaQuest
  • ALPHV leaking internal comm's related to victims incident response
  • High Severity vulnerability affecting Veeam back servers exploited in the wild (CVE-2023-27532)
Weekly: RQ Ransomware Report, 3CX Update, Russia-Ukraine Cyber Operations, and Cybercriminal Ecosystems28 Apr 202300:47:10

In this episode of ShadowTalk, host Stefano, along with Kim, Ivan, and Brandon, discuss the latest news in cyber security and threat research. Topics this week include:

  • Highlights from the ReliaQuest Ransomware Quarterly Report Q1 2023
  • A supply-chain of a supply-chain: 3CX Update
  • Analysis of Russia-Ukraine cyber operations
  • A look into recent shifts in the cybercriminal ecosystem

Resources:

Akira’s Zero-Day Chaos + The Rise of DRP Threats06 Aug 202500:28:43

Akira ransomware group is exploiting potential zero-day vulnerabilities, and digital risk protection (DRP) threats are rapidly evolving. Join host Joey, along with intelligence analysts John and Hayden, as they dive into:

  • Akira Ransomware Exploiting a Potential Zero Day
  • Plague Backdoor Emerges as Silent Intruder
  • Evolving Tactics of North Korean Attacker
  • DRP Threats Surge Amid Organizational Growth

Resources: https://linktr.ee/ReliaQuestShadowTalk

Joseph Keyes: Joseph Keyes is a Cyber Threat Intelligence Analyst at ReliaQuest, specializing in technical cyber threat research. With his prior role as a Cyber Security Analyst, he has gained years of experience in triaging and responding to active threats using GreyMatter's various tools. Joseph is skilled in intrusion response, threat actor profiling, OSINT across the clear and dark web, and analyzing adversarial TTPs. 

John Dilgen: John Dilgen is a Cyber Threat Intelligence Analyst at ReliaQuest, where he specializes in researching cyber threats impacting ReliaQuest customers. With a strong technical background, he previously served as an Incident Response Analyst and Trainer at ReliaQuest. 

Hayden Evans: Hayden Evans is a Cyber Threat Intelligence Analyst at ReliaQuest. He has experience in the F3EAD lifecycle and analyzing adversaries' TTPs to operationalize this information. He is also experienced with intrusion response, OSINT investigations, and offensive security. 

Special: RSA Conference 202326 Apr 202300:18:27

In this episode, host and CISO Rick Holland is joined by ReliaQuest's Chief Technical Officer Joe Partlow and Chief Strategy Officer Jason Pfeiffer to discuss 

  • cyber trends they're seeing across RSA Conference 2023
  • the benefits of such an event
  • AI in cyber and more.
Weekly: Vulnerability Quarterly Roundup, Domino Backdoor, Lockbit Targeting MacOS21 Apr 202300:37:55

In this episode of ShadowTalk, host Chris Morgan, along with Dani and Dean Murphy, discuss the latest news in cyber security and threat research. Topics this week include:

  • A breakdown of ReliaQuest's latest Vulnerability quarterly report
  • Aftermath of the ransomware attack affecting Capita
  • The "Domino" Backdoor and "Project Nemesis" information stealing malware
  • Lockbit targeting macOS

Resources:

Weekly: Cobalt Strike takedown, latest MERCURY campaign, Patch Tuesday14 Apr 202300:34:52

In this episode of ShadowTalk, host Stefano, along with Caroline and Kitch, discuss the latest news in cyber security and threat research. Topics this week include:

  • A new approach in malicious infrastructure takedown
  • The latest TTPs of MERCURY aka MuddyWater
  • What's new on this Patch Tuesday?

Resources:

Weekly: Genesis Market seizure, Vulkan Files, and new Microsoft Security Update07 Apr 202300:22:55

In this episode of ShadowTalk, host Stefano, along with Ivan and Corey, discuss the latest news in cyber security and threat research. Topics this week include:

  • The prominent Genesis Market has been seized: What's next?
  • Confidential Vulkan Files expose ties between Russian APTs and private sector
  • Microsoft mitigates malicious attachments delivered via OneNote

Resources:

Weekly: 3CX supply chain attack, Rostec deanonymize Telegram, IcedID30 Mar 202300:33:37

In this early released episode of ShadowTalk, host Chris Morgan, along with ReliaQuest CISO Rick Holland, Kim Bromley, and Colin Ferris discuss the latest news in cyber security and threat research. Topics this week include:

  • Implications from the 3CX supply-chain attack and what you need to do going forward
  • Russian telco Rostec de-anonymizing Telegram users
  • Updates to the IcedID malware

Resources:

  • https://www.3cx.com/community/threads/3cx-desktopapp-security-alert.119951/
  • https://www.reliaquest.com/blog/3cx-trojan-attack/
  • https://www.bleepingcomputer.com/news/security/russia-s-rostec-allegedly-can-de-anonymize-telegram-users/
  • https://www.bleepingcomputer.com/news/security/new-icedid-variants-shift-from-bank-fraud-to-malware-delivery/



Weekly: Outlook Vulnerability, TeamTNT and Breachforums closure24 Mar 202300:27:38

In this episode of ShadowTalk, host Chris Morgan, along with Ivan Righi and Caroline Fenstermacher, discuss the latest news in the cyber security and the information security landscape. Topics this week include:

  • Implications following the arrest of BreachForums administrator Pompompurin
  • Cryptojacking activity group the TeamTNT threat group 
  • Microsoft Outlook bug CVE-2023-23397


Resources:

Weekly: SVB collapse, FBI IC3 report, and Cl0p update17 Mar 202300:36:59

In this episode of ShadowTalk, host Stefano De Blasi, along with Rick Holland and Brandon Tirado, discuss cyber threats related to the SVB collapse, the FBI IC3 report and Cl0p ransomware: zero-day vulnerability and victims.

Resources: 

Weekly: US National Cybersecurity Strategy, Emotet and Cl0p return17 Mar 202300:31:48

In this episode of ShadowTalk, host Stefano, along with Caroline and Dean, discuss:

  • the new US National Cybersecurity Strategy
  • the return of Emotet
  • zero-day exploited by the Cl0p ransomware group.
Weekly: HTML Smuggling, CISA Guidance on Logging17 Mar 202300:38:54

This weeks ShadowTalk host Chris, along with Rick, Kitch and Corey, discuss:

  • the email threat of HTML Smuggling
  • the latest guidance on logging from CISA.
Weekly: Russia-Ukraine War - One-Year Later24 Feb 202300:37:30

This week's ShadowTalk podcast covers the latest developments and implications of the Russian-Urkaine War.

Resources:

  • https://resources.digitalshadows.com/weekly-intelligence-summary/weekly-intelligence-summary-24-feb
Full CrushFTP Attack Chain, Plus BreachForums is Back!30 Jul 202500:27:44

Resources: https://linktr.ee/ReliaQuestShadowTalk

Curious how the latest CrushFTP exploit works? Join host Kim along with intelligence analyst Hayden and threat hunter Leo as they discuss:

  • BreachForums Back, XSS Out (1:28)
  • Warlock Ransomware Hits SharePoint (5:28)
  • Fire Ant Stings ESXi (9:39)
  • ReliaQuest Uncovers CrushFTP Attack Chain (13:35

Kim Bromley: Senior Cyber Threat Intelligence Analyst on the ReliaQuest Threat Research Team. She joined ReliaQuest in June 2020 following a 10-year career in UK law enforcement, and has acted as host since 2024.  Kim brings a wealth of experience in threat intelligence and law enforcement tactics, providing unique insights.

Hayden Evans: Cyber Threat Intelligence Analyst at ReliaQuest. He has experience in the F3EAD lifecycle and analyzing adversaries' TTPs to operationalize this information. He is also experienced with intrusion response, OSINT investigations, and offensive security.

Leo Dawson: Threat Hunter on the ReliaQuest Threat Research Team. With a deep background in Experimental Physics and Artificial Intelligence, Leo brings a unique interdisciplinary perspective to cybersecurity. He is driven by a passion for leveraging these skills to proactively track, analyze, and understand threat actor campaigns while gaining deeper insights into their evolving tactics and behaviors. 

Weekly: Trickbot/Conti Sanctions, OneNote Documents, and NATO DDoS Attacks17 Feb 202300:29:41

This week's ShadowTalk podcast covers the latest in the Trickbot/Conti Sanctions, OneNote Documents, NATO DDoS Attacks.

Resources:

  • https://resources.digitalshadows.com/weekly-intelligence-summary/weekly-intelligence-summary-17-feb
Weekly: VMware ESXI campaign and SocGholish overview10 Feb 202300:42:54

This week's ShadowTalk podcast covers the latest in the VMware ESXI Ransomware campaign, Killnet, SocGholish, and more. 

Resources:

  • https://resources.digitalshadows.com/weekly-intelligence-summary/weekly-intelligence-summary-10-feb
Weekly: Hive Ransomware Takedown and Dark Web Cybercriminal Jobs03 Feb 202300:32:19

This week's ShadowTalk podcast covers the latest in the Hive ransomware takedown and dark web cybercriminal forum.

Resources: 

  • https://resources.digitalshadows.com/weekly-intelligence-summary/weekly-intelligence-summary-3-feb
© My Podcast Data