Explore every episode of the podcast ShadowTalk: Powered by ReliaQuest
| Title | Pub. Date | Duration | |
|---|---|---|---|
| CISO Wisdom: Turning Security Investments Into Measurable Risk Reduction | 30 Sep 2026 | 00:33:13 | |
Security teams are contending with more tools, alerts, and vulnerabilities than ever—but volume does not necessarily equal security. Jigar Shah joins us to discuss how organizations can automate repetitive work, prioritize vulnerabilities based on business risk, build identity-driven security strategies, and connect cybersecurity investments to measurable outcomes. With two decades of leadership experience across healthcare, financial services, retail, and consulting, Jigar brings a business-focused perspective on helping security leaders communicate risk and resilience to the board and C-suite. A Question Your Organization Should Be Asking Right Now:
Resources: https://linktr.ee/ReliaQuestShadowTalk Jigar Shah: Transformational IT, data, and cybersecurity executive with two decades of leadership experience across healthcare, financial services, retail, and consulting. He brings a distinctive blend of technology, business, and legal expertise to overseeing complex enterprise initiatives, including cybersecurity programs, cloud migrations, M&A integrations, and risk management for large regulated organizations. A passionate advocate for automation, identity-driven security, and business-aligned cyber strategy, Jigar excels at translating technical priorities into measurable outcomes for boards and C-suite leaders. John Dilgen: Cyber Threat Intelligence Analyst at ReliaQuest, where he specializes in researching cyber threats impacting ReliaQuest customers. With a strong technical background, he previously served as an Incident Response Analyst and Trainer at ReliaQuest. | |||
| Fake NDAs, Real Money: Inside the M&A Social Engineering Playbook | 23 Sep 2026 | 00:28:07 | |
In this episode, we examine the Phantom Deal campaign, in which threat actors used publicly available details about companies’ acquisition histories, subsidiaries, executives, and employees to create convincing fake M&A scenarios. The goal: persuade employees to initiate large financial transfers while keeping conversations off corporate communication channels. We also cover a recent series of zero-day disclosures affecting major endpoint-security and Windows products. These vulnerabilities reinforce a critical operational reality: organizations must be prepared to detect and respond even when endpoint-security visibility is weakened or unavailable. Two questions your organization should be asking right now:
Resources: https://linktr.ee/ReliaQuestShadowTalk John Dilgen: Cyber Threat Intelligence Analyst at ReliaQuest, where he specializes in researching cyber threats impacting ReliaQuest customers. With a strong technical background, he previously served as an Incident Response Analyst and Trainer at ReliaQuest. Brandon Tirado: Director of GreyMatter Operations for ReliaQuest. A skilled cyber defense professional with a unique combination of management and hands-on experience. With a deep understanding of adversary motives and the tactics, techniques, and procedures (TTPs) they use to achieve their goals, Brandon enjoys operationalizing his knowledge to make it more difficult for adversaries to operate within the environments of ReliaQuest customers. His managerial and hands-on experience enriches ShadowTalk with practical and strategic viewpoints. | |||
| From Vulnerability Research to Domain Admin in Minutes | 16 Sep 2026 | 00:31:25 | |
AI is changing the economics of cyberattacks. In this episode, we examine how a suspected threat actor used AI agents to accelerate PaperCut vulnerability research, exploit development, target identification, and post-compromise activity—moving from initial access to domain administrator access in as little as seven minutes. We also explore recent reporting on large-scale AI-model distillation campaigns by China-based companies and what the increasing availability of frontier-level AI capabilities could mean for future nation-state and criminal threat operations. Two questions your organization should be asking right now:
Resources: https://linktr.ee/ReliaQuestShadowTalk John Dilgen: Cyber Threat Intelligence Analyst at ReliaQuest, where he specializes in researching cyber threats impacting ReliaQuest customers. With a strong technical background, he previously served as an Incident Response Analyst and Trainer at ReliaQuest. Alexandra Moore: Manager of Threat Intelligence at ReliaQuest, where she leads intelligence analysis and customer dissemination to help organizations understand and respond to emerging cyber threats. Prior to this, she established and scaled monitoring across Russian-language cybercriminal platforms at Digital Shadows, building collection and analytical coverage to support digital risk protection capabilities. | |||
| One Empty Field: The Email Security Bypass Letting Attackers Impersonate Your Executives | 09 Sep 2026 | 00:29:54 | |
Organizations rely on Microsoft 365's RejectDirectSend control to block internal email spoofing—but a structural gap lets attackers walk right past it. With nothing more than a basic Python script and an empty envelope sender, threat actors are impersonating executives, IT support, and finance teams to launch Business Email Compromise, payment fraud, and follow-on account takeover. Join hosts Alexandra Moore and John Dilgen as they discuss:
Two questions your organization should be asking right now:
Resources: https://linktr.ee/ReliaQuestShadowTalk John Dilgen: Cyber Threat Intelligence Analyst at ReliaQuest, where he specializes in researching cyber threats impacting ReliaQuest customers. With a strong technical background, he previously served as an Incident Response Analyst and Trainer at ReliaQuest. Alexandra Moore: Manager of Threat Intelligence at ReliaQuest, where she leads intelligence analysis and customer dissemination to help organizations understand and respond to emerging cyber threats. Prior to this, she established and scaled monitoring across Russian-language cybercriminal platforms at Digital Shadows, building collection and analytical coverage to support digital risk protection capabilities. | |||
| From Data Dumps to Critical Findings: The New Era of Data Extortion | 02 Sep 2026 | 00:28:56 | |
Threat actors do not see old email archives, forgotten shared drives, and outdated CRM exports as clutter. They see them as searchable inventory. With AI-assisted analysis, attackers can rapidly identify sensitive communications, regulatory exposure, customer relationships, and credentials buried in stolen data. Join hosts John Dilgen and Brandon Tirado as they discuss:
Two questions your organization should be asking right now:
John Dilgen: Cyber Threat Intelligence Analyst at ReliaQuest, where he specializes in researching cyber threats impacting ReliaQuest customers. With a strong technical background, he previously served as an Incident Response Analyst and Trainer at ReliaQuest.
| |||
| Vishing at Scale: Inside the Criminal SaaS Platform Enabling Account Takeover | 26 Aug 2026 | 00:31:13 | |
What if a threat actor already knew your name, your job title, your manager's name, and your direct number before they ever picked up the phone? That's not a hypothetical — that's Work Panel. A new report gave us a rare inside look at the criminal SaaS platform enabling vishing campaigns at scale, and the findings are a wake-up call.
Join hosts John Dilgen and Alexandra Moore as they break down: ✅ How Work Panel packages phishing infrastructure, team management, and real-time credential capture into a single automated console ✅ Why threat actors are now impersonating HR to make their calls more convincing ✅ How legitimate B2B platforms are being weaponized to personalize attacks before a single call is made ✅ The specific controls that can stop these campaigns before they reach your users
🔑 Two questions your organization should be asking right now:
👉 Tune in for expert insights and practical takeaways: ShadowTalk – ReliaQuest 👉 Find more podcast platforms, resources, and our listener feedback survey: ShadowTalk Official: X | Linktree | |||
| Nation-State Actors: Iran’s PLC Attacks, Russia’s Zero-Click Email Exploit, and North Korea’s Fake Employees | 19 Aug 2026 | 00:27:12 | |
Three nation-states. Three distinct playbooks. Iranian actors are targeting internet-exposed industrial controllers and disabling critical safety systems. A Russian threat group built a zero-click email exploit that steals 90 days of inbox data the moment a user views a message. And North Korean operatives are applying for software-development jobs at Western companies—and getting hired. Join hosts John Dilgen and Tehman Tariq as they break down: ✅ How Iranian actors manipulate PLC safety logic while keeping operators in the dark ✅ Why Russia’s zero-click exploit creates a major email-security and data-exfiltration risk ✅ How North Korean operatives use forged and stolen identities to infiltrate organizations as employees 🔑 Two questions your organization should be asking right now:
👉 Tune in for expert insights and practical takeaways: ShadowTalk – ReliaQuest 👉 Find more podcast platforms, resources, and our listener feedback survey: ShadowTalk Official: X | Linktree | |||
| When AI Escapes the Lab: The Hugging Face Breach, PyPI Malware, and What It Means for Defenders | 12 Aug 2026 | 00:23:48 | |
Fully autonomous attacks are here. AI agents escape a test environment, exploit zero-days, coordinate through shared infrastructure, and breach a production company—generating more than 17,000 security events along the way. Elsewhere, another model autonomously publishes malware to PyPI, while AI agents target real open-source developers with tailored social engineering. Join hosts John Dilgen and Tehman Tariq as they break down: ✅ How AI agents escaped containment and compromised Hugging Face infrastructure ✅ Why Claude’s autonomous PyPI attack signals growing software-supply-chain risk ✅ How coordinated AI agents deceived real developers 🔑 Two questions your organization should be asking right now:
👉 Tune in for expert insights and practical takeaways: ShadowTalk – ReliaQuest 👉 Find more podcast platforms, resources, and our listener feedback survey: ShadowTalk Official: X | Linktree | |||
| The Gentlemen, Deadlock, and Clop: The Groups Driving Ransomware & Extortion in 2026 | 05 Aug 2026 | 00:36:29 | |
An affiliate receives a ready-made intrusion kit — pre-compromised targets, an EDR killer, and a full deployment workflow included. No building from scratch. No long ramp-up. Just deploy, observe, and iterate. That's the future of ransomware; it's how the new number-one group operated in Q2 2026. And it's just one of three stories reshaping the extortion landscape right now. Join hosts Brandon Tirado and John Dilgen as they break down:
Two questions your organization should be asking right now:
John Dilgen: Cyber Threat Intelligence Analyst at ReliaQuest, where he specializes in researching cyber threats impacting ReliaQuest customers. With a strong technical background, he previously served as an Incident Response Analyst and Trainer at ReliaQuest. Brandon Tirado: Director of GreyMatter Operations for ReliaQuest. A skilled cyber defense professional with a unique combination of management and hands-on experience. With a deep understanding of adversary motives and the tactics, techniques, and procedures (TTPs) they use to achieve their goals, Brandon enjoys operationalizing his knowledge to make it more difficult for adversaries to operate within the environments of ReliaQuest customers. His managerial and hands-on experience enriches ShadowTalk with practical and strategic viewpoints. | |||
| Compromised Hotel Gateways, Fake Microsoft Domains, and the APT28-Adjacent Campaign That Bypasses MFA Without a Phishing Click | 29 Jul 2026 | 00:31:25 | |
An employee connects to hotel Wi-Fi, receives a familiar Microsoft 365 sign-in prompt, and authenticates. No phishing email. No malicious link. No suspicious attachment. Yet an attacker walks away with a valid, MFA-satisfied session token. Join hosts Alexandra Moore and John Dilgen as they break down:
Two questions your organization should be asking right now:
John Dilgen: Cyber Threat Intelligence Analyst at ReliaQuest, where he specializes in researching cyber threats impacting ReliaQuest customers. With a strong technical background, he previously served as an Incident Response Analyst and Trainer at ReliaQuest. Alexandra Moore: Manager of Threat Intelligence at ReliaQuest, where she leads intelligence analysis and customer dissemination to help organizations understand and respond to emerging cyber threats. Prior to this, she established and scaled monitoring across Russian-language cybercriminal platforms at Digital Shadows, building collection and analytical coverage to support digital risk protection capabilities. | |||
| The Largest Patch Tuesday Ever: 622 CVEs, a 1,380% Phishing Surge, and the Two-Front War on Initial Access | 22 Jul 2026 | 00:28:02 | |
Defenders aren't losing ground on one front, they're losing it on two at once. The largest Patch Tuesday in history just dropped alongside a 1,380% surge in phishing, and threat actors aren't waiting for you to catch up. Join hosts Alexandra Moore and John Dilgen as they break down:
Two questions your organization should be asking right now:
Resources: https://linktr.ee/ReliaQuestShadowTalk John Dilgen: Cyber Threat Intelligence Analyst at ReliaQuest, where he specializes in researching cyber threats impacting ReliaQuest customers. With a strong technical background, he previously served as an Incident Response Analyst and Trainer at ReliaQuest. Alexandra Moore: Manager of Threat Intelligence at ReliaQuest, where she leads intelligence analysis and customer dissemination to help organizations understand and respond to emerging cyber threats. Prior to this, she established and scaled monitoring across Russian-language cybercriminal platforms at Digital Shadows, building collection and analytical coverage to support digital risk protection capabilities. | |||
| FortiBleed, 70,000 Compromised Devices, and the Credential Economy Powering Every Breach | 15 Jul 2026 | 00:22:51 | |
When a 20-person team using AI, automated tools, and a list of default credentials compromised 70,000 devices across 194 countries they exposed how mature the criminal market behind credential theft has become. Initial access brokers are now packaging pre-validated enterprise access for an average of $113,000, and the window from information stealer infection to ransomware deployment is just seven days. Join hosts Tehman Tariq and John Dilgen as they break down:
Two questions your organization should be asking right now:
Resources: https://linktr.ee/ReliaQuestShadowTalk Tehman Tariq: Sr. Manager of Cyber Operations at ReliaQuest. He has spent a majority of my career leading our Incident Response, Security Architecture, and Detection teams. As well has working hand in hand with CISOs to introduce automation allowing for the maturity of their security programs. John Dilgen: Cyber Threat Intelligence Analyst at ReliaQuest, where he specializes in researching cyber threats impacting ReliaQuest customers. With a strong technical background, he previously served as an Incident Response Analyst and Trainer at ReliaQuest. | |||
| Inside Conti's Leaked Chats: 300,000 Messages, a Criminal Empire, and the Ransomware Playbook Still Running Today | 08 Jul 2026 | 00:42:32 | |
When 300,000 internal messages from the world's most prolific ransomware gang were leaked, they exposed more then a shadowy underground network, a full company. HR departments. Conti operated with the structure of a mid-sized software firm, and that changes how defenders need to think about the ransomware landscape today. Join host John and special guest Geoff White, journalist and author of Rinsed, as they discuss:
Two questions your organization should be asking right now:
Resources: https://linktr.ee/ReliaQuestShadowTalk Geoff White: One of the world's leading journalists covering organized crime and technology, with decades of experience investigating fraudsters, hackers, and money launderers. His work has been featured by BBC News, Sky News, Audible, and The Sunday Times, and he has delivered over 300 keynote talks across more than a dozen countries for global brands including Microsoft, HSBC, and Mastercard. He is the author of three books, including The Lazarus Heist — which spawned a hit BBC podcast that ranked number one in the UK Apple charts — and his latest, Rinsed (2024), which The Financial Times called "Riveting." Geoff brings a rare investigative lens to cybercrime, giving ShadowTalk listeners an inside look at the criminal enterprises shaping today's threat landscape. John Dilgen: Cyber Threat Intelligence Analyst at ReliaQuest, where he specializes in researching cyber threats impacting ReliaQuest customers. With a strong technical background, he previously served as an Incident Response Analyst and Trainer at ReliaQuest. | |||
| How Hackers Are Using AI Right Now: Faster Attacks, Smarter Malware, and a New Arms Race | 01 Jul 2026 | 00:25:18 | |
AI is not replacing threat actors, instead it is making them faster, cheaper, and harder to stop. From AI powered phishing campaigns generating thousands of pages simultaneously, to a newly discovered macOS implant called Gaslight that injects fabricated system error messages into AI powered triage pipelines, the arms race between attackers and defenders is accelerating. The question is not whether AI is being used against your organization. It is whether your defenses are keeping pace. Join hosts Brandon and John as they discuss:
Two questions your organization should be asking right now: • How long does it actually take your team to detect and contain a critical severity alert? • Are your detections layered across enough diverse log sources? Resources: https://linktr.ee/ReliaQuestShadowTalk John Dilgen: Cyber Threat Intelligence Analyst at ReliaQuest, where he specializes in researching cyber threats impacting ReliaQuest customers. With a strong technical background, he previously served as an Incident Response Analyst and Trainer at ReliaQuest. Brandon Tirado: Director of GreyMatter Operations for ReliaQuest. A skilled cyber defense professional with a unique combination of management and hands-on experience. With a deep understanding of adversary motives and the tactics, techniques, and procedures (TTPs) they use to achieve their goals, Brandon enjoys operationalizing his knowledge to make it more difficult for adversaries to operate within the environments of ReliaQuest customers. His managerial and hands-on experience enriches ShadowTalk with practical and strategic viewpoints. | |||
| Klue, Kali365, OAuth: When the Front Door Is a Trusted Integration | 24 Jun 2026 | 00:28:08 | |
In the Klue compromises threat actors walked in through a trusted integration, using legitimate credentials to quietly siphon Salesforce CRM data at scale. The challenge isn't just responding to Klue. It's recognizing that every OAuth-connected integration in your environment is part of your attack surface. Join hosts Alexandra and John as they discuss:
Two questions your organization should be asking right now:
Resources: https://linktr.ee/ReliaQuestShadowTalk John Dilgen: Cyber Threat Intelligence Analyst at ReliaQuest, where he specializes in researching cyber threats impacting ReliaQuest customers. With a strong technical background, he previously served as an Incident Response Analyst and Trainer at ReliaQuest. Alexandra Moore: Manager of Threat Intelligence at ReliaQuest, where she leads intelligence analysis and customer dissemination to help organizations understand and respond to emerging cyber threats. Prior to this, she established and scaled monitoring across Russian-language cybercriminal platforms at Digital Shadows, building collection and analytical coverage to support digital risk protection capabilities. | |||
| ShinyHunters' Expanding Toolkit: Oracle PeopleSoft Zero-Day Exploitation and the BreachForums Defense Gaps | 17 Jun 2026 | 00:19:39 | |
ShinyHunters dominated headlines this week: a zero-day, a BreachForums listing, and unverified claims all hitting at once. The problem isn't just keeping up with the volume. It's knowing which of it is real, which is noise, and what your team actually needs to act on. Join hosts Tehman and John as they discuss:
Two questions your organization should be asking right now:
Resources: https://linktr.ee/ReliaQuestShadowTalk John Dilgen: Cyber Threat Intelligence Analyst at ReliaQuest, where he specializes in researching cyber threats impacting ReliaQuest customers. With a strong technical background, he previously served as an Incident Response Analyst and Trainer at ReliaQuest. Tehman Tariq: Sr. Manager of Cyber Operations at ReliaQuest. He has spent a majority of my career leading our Incident Response, Security Architecture, and Detection teams. As well has working hand in hand with CISOs to introduce automation allowing for the maturity of their security programs. | |||
| China-Linked Cyber Espionage: How OP-512 Exploited Legacy IIS Servers and Evaded Detection | 10 Jun 2026 | 00:23:08 | |
Your team built defenses around known China-linked clusters. The file hashes are tracked. The behavioral patterns are documented. What those weren't built to catch is a new cluster that studied those exact defenses and engineered around them. A China-linked attacker compromised an internet-facing IIS server, maintained access for over 75 days, and came back on fresh infrastructure. With four China-linked clusters converging on the same legacy IIS stack in twelve months, defenders building detection programs around yesterday's cluster are already behind the next one. Join hosts Alex and John as they discuss:
Two questions your organization should be asking right now:
Resources: https://linktr.ee/ReliaQuestShadowTalk Alexandra Moore: Manager of Threat Intelligence at ReliaQuest, where she leads intelligence analysis and customer dissemination to help organizations understand and respond to emerging cyber threats. Prior to this, she established and scaled monitoring across Russian-language cybercriminal platforms at Digital Shadows, building collection and analytical coverage to support digital risk protection capabilities. John Dilgen: Cyber Threat Intelligence Analyst at ReliaQuest, where he specializes in researching cyber threats impacting ReliaQuest customers. With a strong technical background, he previously served as an Incident Response Analyst and Trainer at ReliaQuest. | |||
| SonicWall, MFA Bypass, IABs: Why Patched Devices Are Still Handing Attackers Initial Access | 03 Jun 2026 | 00:20:51 | |
Your team patches the device. The firmware version matches the advisory. The ticket closes. The device comes off the remediation queue. What your workflow never tracked is that the advisory also required six manual LDAP configuration steps — and without them, the authentication bypass still works. An initial access broker authenticated through the VPN, reached a domain-joined file server, and was gone in under 40 minutes. Your dashboard still showed a clean queue. With initial access brokers operating on disciplined, sub-hour timelines and patch-management workflows built around a single completion step, defenders are closing tickets on devices that are still wide open. Join hosts Tehman and John as they discuss:
Two questions your organization should be asking right now:
Tune in for expert insights, practical takeaways, and the full threat report: https://linktr.ee/ReliaQuestShadowTalk Tehman Tariq: Sr. Manager of Cyber Operations at ReliaQuest. He has spent a majority of my career leading our Incident Response, Security Architecture, and Detection teams. As well has working hand in hand with CISOs to introduce automation allowing for the maturity of their security programs. | |||
| Device Code, OAuth, PhaaS: How Session Token Theft is Breaking the Phishing Playbook | 27 May 2026 | 00:29:22 | |
Your user clicked a link, landed on a real Microsoft login page, typed their password, completed MFA, and walked away thinking nothing happened. Somewhere across the internet, an attacker's device just received an authenticated session token. The password is irrelevant. The MFA prompt already fired and passed. With PhaaS platforms now converging on token-theft tradecraft and post-compromise automation executing in seconds, defenders are racing a scripted attacker with a manual playbook. Join hosts Brandon and John as they discuss:
Two questions your organization should be asking right now:
Resources: https://linktr.ee/ReliaQuestShadowTalk Brandon Tirado: Director of GreyMatter Operations for ReliaQuest. A skilled cyber defense professional with a unique combination of management and hands-on experience. With a deep understanding of adversary motives and the tactics, techniques, and procedures (TTPs) they use to achieve their goals, Brandon enjoys operationalizing his knowledge to make it more difficult for adversaries to operate within the environments of ReliaQuest customers. His managerial and hands-on experience enriches ShadowTalk with practical and strategic viewpoints. John Dilgen: Cyber Threat Intelligence Analyst at ReliaQuest, where he specializes in researching cyber threats impacting ReliaQuest customers. With a strong technical background, he previously served as an Incident Response Analyst and Trainer at ReliaQuest. | |||
| SQLite, Mistral, OpenAI: How AI Attacks Are Reshaping the Attack Surface | 20 May 2026 | 00:19:48 | |
What happens when an AI agent uncovers a zero-day in hours instead of weeks, and state-backed groups are already operationalizing the same tools? With self-hosted AI infrastructure sprawling outside asset registers and supply chain worms reaching inside AI vendors themselves, defenders need a new operating model. Join hosts Tehman and John as they discuss:
Two questions your organization should be asking right now:
Resources: https://linktr.ee/ReliaQuestShadowTalk John Dilgen: Cyber Threat Intelligence Analyst at ReliaQuest, where he specializes in researching cyber threats impacting ReliaQuest customers. With a strong technical background, he previously served as an Incident Response Analyst and Trainer at ReliaQuest. Tehman Tariq: Sr. Manager of Cyber Operations at ReliaQuest. He has spent a majority of my career leading our Incident Response, Security Architecture, and Detection teams. As well has working hand in hand with CISOs to introduce automation allowing for the maturity of their security programs. | |||
| Canvas, Trellix, Mini Shai-Hulud: How Defenders Respond When Supply Chain Attacks Become Weekly | 14 May 2026 | 00:31:31 | |
What's driving the surge in weekly supply chain attacks, and why does the real defender problem start after the supplier gets hit? With 275 million records exposed and 8,809 institutions caught in the downstream fallout, organizations need a new playbook. Join hosts Alexandra and John as they discuss:
Two questions your organization should be asking right now:
Resources: https://linktr.ee/ReliaQuestShadowTalk John Dilgen: Cyber Threat Intelligence Analyst at ReliaQuest, where he specializes in researching cyber threats impacting ReliaQuest customers. With a strong technical background, he previously served as an Incident Response Analyst and Trainer at ReliaQuest. Alexandra Moore: Manager of Threat Intelligence at ReliaQuest, where she leads intelligence analysis and customer dissemination to help organizations understand and respond to emerging cyber threats. Prior to this, she established and scaled monitoring across Russian-language cybercriminal platforms at Digital Shadows, building collection and analytical coverage to support digital risk protection capabilities. | |||
| Akira, ShinyHunters, and The Gentlemen: Extortion Lessons From Early 2026 | 06 May 2026 | 00:34:55 | |
What factors have driven the top ransomware and extortion groups' success in early 2026? And how should organizations structure their defenses to protect against them? Join hosts Alexandra and John as they discuss:
Two questions your organization should be asking right now:
Resources: https://linktr.ee/ReliaQuestShadowTalk John Dilgen: Cyber Threat Intelligence Analyst at ReliaQuest, where he specializes in researching cyber threats impacting ReliaQuest customers. With a strong technical background, he previously served as an Incident Response Analyst and Trainer at ReliaQuest. Alexandra Moore: Manager of Threat Intelligence at ReliaQuest, where she leads intelligence analysis and customer dissemination to help organizations understand and respond to emerging cyber threats. Prior to this, she established and scaled monitoring across Russian-language cybercriminal platforms at Digital Shadows, building collection and analytical coverage to support digital risk protection capabilities. | |||
| What Happened to Black Basta's Playbook? The Automated Teams Phishing Threat Hitting Executives | 29 Apr 2026 | 00:26:36 | |
Black Basta disbanded in February 2025, but their playbook didn't go with them. In March 2026, 77% of observed incidents targeted executives and directors, and attackers moved from first contact to malicious script execution in as little as 12 minutes. The tactic has been automated, refined, and is now running faster than most SOCs can respond. Join hosts Alexandra and John as they discuss:
Two questions your organization should be asking right now:
Resources: https://linktr.ee/ReliaQuestShadowTalk John Dilgen: Cyber Threat Intelligence Analyst at ReliaQuest, where he specializes in researching cyber threats impacting ReliaQuest customers. With a strong technical background, he previously served as an Incident Response Analyst and Trainer at ReliaQuest. Alexandra Moore: Manager of Threat Intelligence at ReliaQuest, where she leads intelligence analysis and customer dissemination to help organizations understand and respond to emerging cyber threats. Prior to this, she established and scaled monitoring across Russian-language cybercriminal platforms at Digital Shadows, building collection and analytical coverage to support digital risk protection capabilities. | |||
| Did ShinyHunters Compromise Vercel? Every CISO's Cloud Security Visibility Problem | 22 Apr 2026 | 00:25:20 | |
89% of organizations that suffered a SaaS breach last year believed they had appropriate visibility. They had the logs — what they lacked was detection on what mattered. The Vercel incident shows exactly how costly that gap can be. Join hosts Brandon and John as they discuss:
Resources: https://linktr.ee/ReliaQuestShadowTalk John Dilgen: Cyber Threat Intelligence Analyst at ReliaQuest, where he specializes in researching cyber threats impacting ReliaQuest customers. With a strong technical background, he previously served as an Incident Response Analyst and Trainer at ReliaQuest. Brandon Tirado: Director of GreyMatter Operations for ReliaQuest. Brandon is a skilled cyber defense professional with a unique combination of management and hands-on experience. With a deep understanding of adversary motives and the tactics, techniques, and procedures (TTPs) they use to achieve their goals, Brandon enjoys operationalizing his knowledge to make it more difficult for adversaries to operate within the environments of ReliaQuest customers. His managerial and hands-on experience enriches ShadowTalk with practical and strategic viewpoints. | |||
| What Claude Mythos Means for Organizations | 15 Apr 2026 | 00:25:37 | |
Resources: https://linktr.ee/ReliaQuestShadowTalk Join hosts John and Alex, alongside special guest and ReliaQuest CTO Joe Partlow, as they discuss:
Joe Partlow: CTO of ReliaQuest, a leading Information Security provider and is currently involved with new product initiatives along with research and development efforts. Joe has been involved the Information Security field for over 30 years, in both the defensive side and offensive capabilities. Current projects include data ingestion/analytics at scale, DFIR automation and generative AI. He is also a regular speaker and contributor at security conferences, groups and associations. Joe has a degree in Computer Information Systems and holds many industry-specific certifications John Dilgen: Cyber Threat Intelligence Analyst at ReliaQuest, where he specializes in researching cyber threats impacting ReliaQuest customers. With a strong technical background, he previously served as an Incident Response Analyst and Trainer at ReliaQuest. Alexandra Moore: Manager of Threat Intelligence at ReliaQuest, where she leads intelligence analysis and customer dissemination to help organizations understand and respond to emerging cyber threats. Prior to this, she established and scaled monitoring across Russian-language cybercriminal platforms at Digital Shadows, building collection and analytical coverage to support digital risk protection capabilities. | |||
| Axios and Trivy — Supply Chain Gaps Organizations Must Fix | 08 Apr 2026 | 00:24:53 | |
Resources: https://linktr.ee/ReliaQuestShadowTalk Join hosts John and Tehman as they break down two of the most consequential supply chain attacks of 2026:
John Dilgen: Cyber Threat Intelligence Analyst at ReliaQuest, where he specializes in researching cyber threats impacting ReliaQuest customers. With a strong technical background, he previously served as an Incident Response Analyst and Trainer at ReliaQuest. Tehman Tariq: Sr. Manager of Cyber Operations at ReliaQuest. He has spent a majority of my career leading our Incident Response, Security Architecture, and Detection teams. As well has working hand in hand with CISOs to introduce automation allowing for the maturity of their security programs. | |||
| Faster, Smarter, and Already Escalated — What It Takes to Defend Against the Modern Threat Landscape | 01 Apr 2026 | 00:33:21 | |
Resources: https://linktr.ee/ReliaQuestShadowTalk Join hosts Alexandra and John, live from Exponent 2026, alongside top security leaders as they discuss:
Chris Thompson: CISO of Caris Life Sciences, a leading, next-generation AI TechBio company and precision medicine pioneer. Chris is a retired Federal Agent having most recently led the North Texas Cyber Task Force for the FBI and was an operator on the FBI Cyber Action Team. Michael Andreano: Sr. Director of Information Security at Hikma Pharmaceuticals, leading their global information security team. He has over 30 years experience in the healthcare and hospitality industries with roles of increasing responsibility at Merck, Wyndham Hotels, Olympus, Syneos Health, and now Hikma the past four years. He also is part of the Evanta C-Suite Information Security Community where he serves as a Governing Body member and active in his local Cloud Security Alliance chapter in Lehigh Valley, Pennsylvania. John Dilgen: Cyber Threat Intelligence Analyst at ReliaQuest, where he specializes in researching cyber threats impacting ReliaQuest customers. With a strong technical background, he previously served as an Incident Response Analyst and Trainer at ReliaQuest. Alexandra Moore: Manager of Threat Intelligence at ReliaQuest, where she leads intelligence analysis and customer dissemination to help organizations understand and respond to emerging cyber threats. Prior to this, she established and scaled monitoring across Russian-language cybercriminal platforms at Digital Shadows, building collection and analytical coverage to support digital risk protection capabilities. | |||
| The Invisible Attack Surface: Iran-Aligned Threat Actors and Corporate Blind Spots | 25 Mar 2026 | 00:19:51 | |
Resources: https://linktr.ee/ReliaQuestShadowTalk Join hosts Brandon and John as they discuss:
John Dilgen: Cyber Threat Intelligence Analyst at ReliaQuest, where he specializes in researching cyber threats impacting ReliaQuest customers. With a strong technical background, he previously served as an Incident Response Analyst and Trainer at ReliaQuest. Brandon Tirado: Brandon Tirado is the Director of GreyMatter Operations for ReliaQuest. Brandon is a skilled cyber defense professional with a unique combination of management and hands-on experience. With a deep understanding of adversary motives and the tactics, techniques, and procedures (TTPs) they use to achieve their goals, Brandon enjoys operationalizing his knowledge to make it more difficult for adversaries to operate within the environments of ReliaQuest customers. His managerial and hands-on experience enriches ShadowTalk with practical and strategic viewpoints. | |||
| The 2026 Annual Threat Report Breakdown, Part 3: The Long Game — Nation-State Threats & What's Coming in 2026 | 18 Mar 2026 | 00:25:07 | |
Resources: https://linktr.ee/ReliaQuestShadowTalk Join hosts John and Alex as they discuss:
John Dilgen: Cyber Threat Intelligence Analyst at ReliaQuest, where he specializes in researching cyber threats impacting ReliaQuest customers. With a strong technical background, he previously served as an Incident Response Analyst and Trainer at ReliaQuest. Alexander Capraro: Alexander Capraro is a Cyber Threat Intelligence Analyst at ReliaQuest with over five years of experience in cybersecurity. With his prior experience as a Security Analyst, he specializes in incident response, malware campaign tracking, and OSINT investigations. | |||
| The 2026 Annual Threat Report Breakdown, Part 2 — Once They're In: Post-Compromise Tactics, Ransomware & Exfiltration | 11 Mar 2026 | 00:26:06 | |
Resources: https://linktr.ee/ReliaQuestShadowTalk Join hosts Tehman and John as they discuss:
John Dilgen: Cyber Threat Intelligence Analyst at ReliaQuest, where he specializes in researching cyber threats impacting ReliaQuest customers. With a strong technical background, he previously served as an Incident Response Analyst and Trainer at ReliaQuest. Tehman Tariq: Sr. Manager of Cyber Operations at ReliaQuest. He has spent a majority of my career leading our Incident Response, Security Architecture, and Detection teams. As well has working hand in hand with CISOs to introduce automation allowing for the maturity of their security programs. | |||
| The 2026 Annual Threat Report Breakdown, Part 1 — How AI Contributes to Attacker Speed, and the Malware That's Winning | 04 Mar 2026 | 00:25:39 | |
Resources: https://linktr.ee/ReliaQuestShadowTalk Join hosts Brandon and John as they discuss:
John Dilgen: Cyber Threat Intelligence Analyst at ReliaQuest, where he specializes in researching cyber threats impacting ReliaQuest customers. With a strong technical background, he previously served as an Incident Response Analyst and Trainer at ReliaQuest. Brandon Tirado: Director of Threat Research for ReliaQuest. A skilled cyber defense professional with a unique combination of management and hands-on experience. With a deep understanding of adversary motives and the tactics, techniques, and procedures (TTPs) they use to achieve their goals, Brandon enjoys operationalizing his knowledge to make it more difficult for adversaries to operate within the environments of ReliaQuest customers. His managerial and hands-on experience enriches ShadowTalk with practical and strategic viewpoints. | |||
| Malware Isn't Required—How Ransomware Groups Turn Legitimate RMMs Into a Weapon | 25 Feb 2026 | 00:21:06 | |
Resources: https://linktr.ee/ReliaQuestShadowTalk Join hosts John and Tehman as they discuss:
John Dilgen: Cyber Threat Intelligence Analyst at ReliaQuest, where he specializes in researching cyber threats impacting ReliaQuest customers. With a strong technical background, he previously served as an Incident Response Analyst and Trainer at ReliaQuest. Tehman Tariq: Sr. Manager of Cyber Operations at ReliaQuest. He has spent a majority of my career leading our Incident Response, Security Architecture, and Detection teams. As well has working hand in hand with CISOs to introduce automation allowing for the maturity of their security programs. | |||
| Ransomware vs. Exfiltration-Only—The Extortion Model Showdown | 18 Feb 2026 | 00:28:24 | |
Resources: https://linktr.ee/ReliaQuestShadowTalk Join hosts Brandon and John as they discuss:
John Dilgen: Cyber Threat Intelligence Analyst at ReliaQuest, where he specializes in researching cyber threats impacting ReliaQuest customers. With a strong technical background, he previously served as an Incident Response Analyst and Trainer at ReliaQuest. Brandon Tirado: Director of Threat Research for ReliaQuest. A skilled cyber defense professional with a unique combination of management and hands-on experience. With a deep understanding of adversary motives and the tactics, techniques, and procedures (TTPs) they use to achieve their goals, Brandon enjoys operationalizing his knowledge to make it more difficult for adversaries to operate within the environments of ReliaQuest customers. His managerial and hands-on experience enriches ShadowTalk with practical and strategic viewpoints. | |||
| Patch Management Is Losing—The Case for Predictive Vulnerability Defense | 11 Feb 2026 | 00:29:08 | |
Resources: https://linktr.ee/ReliaQuestShadowTalk Join hosts Brandon and John as they discuss:
John Dilgen: Cyber Threat Intelligence Analyst at ReliaQuest, where he specializes in researching cyber threats impacting ReliaQuest customers. With a strong technical background, he previously served as an Incident Response Analyst and Trainer at ReliaQuest. Brandon Tirado: Director of Threat Research for ReliaQuest. A skilled cyber defense professional with a unique combination of management and hands-on experience. With a deep understanding of adversary motives and the tactics, techniques, and procedures (TTPs) they use to achieve their goals, Brandon enjoys operationalizing his knowledge to make it more difficult for adversaries to operate within the environments of ReliaQuest customers. His managerial and hands-on experience enriches ShadowTalk with practical and strategic viewpoints. | |||
| Beyond Phishing Emails—Social Engineering Drives Initial Access | 04 Feb 2026 | 00:22:51 | |
Resources: https://linktr.ee/ReliaQuestShadowTalk Join hosts John and Tehman as they discuss:
John Dilgen: Cyber Threat Intelligence Analyst at ReliaQuest, where he specializes in researching cyber threats impacting ReliaQuest customers. With a strong technical background, he previously served as an Incident Response Analyst and Trainer at ReliaQuest. Tehman Tariq: Sr. Manager of Cyber Operations at ReliaQuest. He has spent a majority of my career leading our Incident Response, Security Architecture, and Detection teams. As well has working hand in hand with CISOs to introduce automation allowing for the maturity of their security programs. | |||
| Malicious AI—The New Face of Cyber Threats | 28 Jan 2026 | 00:20:34 | |
Resources: https://linktr.ee/ReliaQuestShadowTalk John and Tehman as they discuss:
John Dilgen: Cyber Threat Intelligence Analyst at ReliaQuest, where he specializes in researching cyber threats impacting ReliaQuest customers. With a strong technical background, he previously served as an Incident Response Analyst and Trainer at ReliaQuest. Tehman Tariq: Sr. Manager of Cyber Operations at ReliaQuest. He has spent a majority of my career leading our Incident Response, Security Architecture, and Detection teams. As well has working hand in hand with CISOs to introduce automation allowing for the maturity of their security programs. | |||
| Maintainer Compromise: The Next Supply-Chain Attack Vector in 2026 | 21 Jan 2026 | 00:27:12 | |
Resources: https://linktr.ee/ReliaQuestShadowTalk Join hosts Brandon and John as they discuss:
Brandon Tirado: Director of Threat Research for ReliaQuest. A skilled cyber defense professional with a unique combination of management and hands-on experience. With a deep understanding of adversary motives and the tactics, techniques, and procedures (TTPs) they use to achieve their goals, Brandon enjoys operationalizing his knowledge to make it more difficult for adversaries to operate within the environments of ReliaQuest customers. His managerial and hands-on experience enriches ShadowTalk with practical and strategic viewpoints. John Dilgen: Cyber Threat Intelligence Analyst at ReliaQuest, where he specializes in researching cyber threats impacting ReliaQuest customers. With a strong technical background, he previously served as an Incident Response Analyst and Trainer at ReliaQuest. | |||
| Kicking Off 2026 with Ransomware Insights and Defense Strategies | 14 Jan 2026 | 00:31:34 | |
Resources: https://linktr.ee/ReliaQuestShadowTalk Join hosts Brandon and Tehman as they discuss:
Brandon Tirado: Director of Threat Research for ReliaQuest. Brandon is a skilled cyber defense professional with a unique combination of management and hands-on experience. With a deep understanding of adversary motives and the tactics, techniques, and procedures (TTPs) they use to achieve their goals, Brandon enjoys operationalizing his knowledge to make it more difficult for adversaries to operate within the environments of ReliaQuest customers. His managerial and hands-on experience enriches ShadowTalk with practical and strategic viewpoints. Tehman Tariq: Sr. Manager of Cyber Operations at ReliaQuest. He has spent a majority of my career leading our Incident Response, Security Architecture, and Detection teams. As well has working hand in hand with CISOs to introduce automation allowing for the maturity of their security programs. | |||
| React2Shell Attacks Evolve, ClickFix Attacks, and Holiday Season Threats | 17 Dec 2025 | 00:31:38 | |
Resources: https://linktr.ee/ReliaQuestShadowTalk Join host John and intelligence analyst Ivan as they discuss:
John Dilgen: Cyber Threat Intelligence Analyst at ReliaQuest, where he specializes in researching cyber threats impacting ReliaQuest customers. With a strong technical background, he previously served as an Incident Response Analyst and Trainer at ReliaQuest. Ivan Righi: Threat Intelligence Analyst at ReliaQuest, specializing in technical cyber threat research. Since joining ReliaQuest in June 2019, Ivan has focused on data breach investigations, automations, threat actor profiling, and reverse engineering threat campaigns. He holds a Master of Science degree in Cybersecurity and a GIAC Reverse Engineering Malware (GREM) certification, bringing technical expertise and actionable insights. | |||
| React2Shell Exploits, CISA’s Brickstorm Warning, ShadyPanda’s Browser Weaponization | 10 Dec 2025 | 00:32:29 | |
Resources: https://linktr.ee/ReliaQuestShadowTalk Join host John along with systems security engineer Corey and intelligence analyst Hayden as they discuss:
John Dilgen: Cyber Threat Intelligence Analyst at ReliaQuest, where he specializes in researching cyber threats impacting ReliaQuest customers. With a strong technical background, he previously served as an Incident Response Analyst and Trainer at ReliaQuest. Corey Carter: Systems Security Engineer at ReliaQuest. A Florida native and former infantryman in the United States Marines, Corey holds a bachelor's degree in computer science with a specialization in information assurance. His experience as a detection researcher, security analyst, and threat hunter at ReliaQuest, combined with his military background, equips him with a unique perspective on cybersecurity challenges. Hayden Evans: Cyber Threat Intelligence Analyst at ReliaQuest. He has experience in the F3EAD lifecycle and analyzing adversaries' TTPs to operationalize this information. He is also experienced with intrusion response, OSINT investigations, and offensive security. | |||
| Scattered Lapsus$ Hunters, SilverFox's ValleyRat Campaign, and More | 03 Dec 2025 | 00:25:01 | |
Resources: https://linktr.ee/ReliaQuestShadowTalk Join host John and intelligence analysts Alex and Hayden as they discuss:
John Dilgen: Cyber Threat Intelligence Analyst at ReliaQuest, where he specializes in researching cyber threats impacting ReliaQuest customers. With a strong technical background, he previously served as an Incident Response Analyst and Trainer at ReliaQuest. Alexander Capraro: Cyber Threat Intelligence Analyst at ReliaQuest with over five years of experience in cybersecurity. With his prior experience as a Security Analyst, he specializes in incident response, malware campaign tracking, and OSINT investigations. Hayden Evans: Cyber Threat Intelligence Analyst at ReliaQuest. He has experience in the F3EAD lifecycle and analyzing adversaries' TTPs to operationalize this information. He is also experienced with intrusion response, OSINT investigations, and offensive security. | |||
| Are Cyber Predictions Worth It? Plus Chinese AI Attacks, IoT Takeovers | 26 Nov 2025 | 00:27:53 | |
Resources: https://linktr.ee/ReliaQuestShadowTalk Do you really need predictions to tackle cyber threats? Join host Kim along with intelligence analyst John & special guest CISO Rafal Baran as they discuss:
Rafal Baran: IT security leader and CISO in the global reinsurance space. He focuses on building practical security and privacy programs across multiple jurisdictions, with an emphasis on cloud security and incident readiness. He advises senior leadership on emerging risks and resilience and holds boardroom certification as a Qualified Technology Expert, along with multiple credentials spanning cybersecurity, privacy, and the re/insurance domains. Outside his role, he mentors upcoming security professionals and contributes to the broader cyber community. Kim Bromley: Senior Cyber Threat Intelligence Analyst on the ReliaQuest Threat Research Team. She joined ReliaQuest in June 2020 following a 10-year career in UK law enforcement, and has acted as host since 2024. Kim brings a wealth of experience in threat intelligence and law enforcement tactics, providing unique insights. John Dilgen: Cyber Threat Intelligence Analyst at ReliaQuest, where he specializes in researching cyber threats impacting ReliaQuest customers. With a strong technical background, he previously served as an Incident Response Analyst and Trainer at ReliaQuest. | |||
| Fortinet Flaw Exposed and Exploited! Plus, Threat Hunter Hacks: SEO Hits Hard | 19 Nov 2025 | 00:29:35 | |
Resources: https://linktr.ee/ReliaQuestShadowTalk Join host Kim, intelligence analyst John, and threat hunter Tristan as they discuss:
Listen on @Listennotes: https://lnns.co/mgbyVjXv7p6 Kim Bromley: Senior Cyber Threat Intelligence Analyst on the ReliaQuest Threat Research Team. She joined ReliaQuest in June 2020 following a 10-year career in UK law enforcement, and has acted as host since 2024. Kim brings a wealth of experience in threat intelligence and law enforcement tactics, providing unique insights. John Dilgen: Cyber Threat Intelligence Analyst at ReliaQuest, where he specializes in researching cyber threats impacting ReliaQuest customers. With a strong technical background, he previously served as an Incident Response Analyst and Trainer at ReliaQuest. Tristan Luikey: Threat Hunter at ReliaQuest, specializing in responding to and mitigating active breaches to safeguard customers' networks. In addition to breach response, Tristan conducts comprehensive research into emerging threats and attack techniques, enabling proactive threat hunting to strengthen organizational security. | |||
| Gootloader's Return, LANDFALL Android Spyware, Sector-by-Sector Cyber Trends | 12 Nov 2025 | 00:34:17 | |
Resources: https://linktr.ee/ReliaQuestShadowTalk Wondering why Gootloader is suddenly back in action? Join host Kim along with intelligence analyst Hayden & Systems Security Engineer Corey as they discuss:
Kim Bromley: Senior Cyber Threat Intelligence Analyst on the ReliaQuest Threat Research Team. She joined ReliaQuest in June 2020 following a 10-year career in UK law enforcement, and has acted as host since 2024. Kim brings a wealth of experience in threat intelligence and law enforcement tactics, providing unique insights. Corey Carter: Detection Researcher at ReliaQuest. A Florida native and former infantryman in the United States Marines, Corey holds a bachelor's degree in computer science with a specialization in information assurance. His experience as a Security Analyst and Threat Hunter at ReliaQuest, combined with his military background, equips him with a unique perspective on cybersecurity challenges. Hayden Evans: Cyber Threat Intelligence Analyst at ReliaQuest. He has experience in the F3EAD lifecycle and analyzing adversaries' TTPs to operationalize this information. He is also experienced with intrusion response, OSINT investigations, and offensive security. | |||
| Why Cloud Threats Are Escalating: Identity Risks, Automation Flaws, and Legacy Vulnerabilities, Plus the Latest on Chinese APT Campaigns and NPM Package Abuse | 05 Nov 2025 | 00:27:18 | |
Resources: https://linktr.ee/ReliaQuestShadowTalk Did you know 99% of cloud identities are over-privileged, creating the perfect storm for attackers to seamlessly infiltrate your environment? Join host Kim along with intelligence analysts John & Alex as they discuss:
Kim Bromley: Senior Cyber Threat Intelligence Analyst on the ReliaQuest Threat Research Team. She joined ReliaQuest in June 2020 following a 10-year career in UK law enforcement, and has acted as host since 2024. Kim brings a wealth of experience in threat intelligence and law enforcement tactics, providing unique insights. John Dilgen: Cyber Threat Intelligence Analyst at ReliaQuest, where he specializes in researching cyber threats impacting ReliaQuest customers. With a strong technical background, he previously served as an Incident Response Analyst and Trainer at ReliaQuest. Alexander Capraro: Alexander Capraro is a Cyber Threat Intelligence Analyst at ReliaQuest with over five years of experience in cybersecurity. With his prior experience as a Security Analyst, he specializes in incident response, malware campaign tracking, and OSINT investigations.
| |||
| Why Cyber Threats Surge 20% During M&A, Plus the Latest on Qilin and Lazarus Group Campaigns | 29 Oct 2025 | 00:31:05 | |
Resources: https://linktr.ee/ReliaQuestShadowTalk Picture this: You close a $50M acquisition on Friday and by Monday, attackers are in your network. Sound far-fetched? It's not. Join host Kim along with intelligence analyst John & Threat Hunter Leo as they discuss:
Kim Bromley: Senior Cyber Threat Intelligence Analyst on the ReliaQuest Threat Research Team. She joined ReliaQuest in June 2020 following a 10-year career in UK law enforcement, and has acted as host since 2024. Kim brings a wealth of experience in threat intelligence and law enforcement tactics, providing unique insights. John Dilgen: Cyber Threat Intelligence Analyst at ReliaQuest, where he specializes in researching cyber threats impacting ReliaQuest customers. With a strong technical background, he previously served as an Incident Response Analyst and Trainer at ReliaQuest. Leo Dawson: Leo Dawson is a Threat Hunter on the ReliaQuest Threat Research Team. With a deep background in Experimental Physics and Artificial Intelligence, Leo brings a unique interdisciplinary perspective to cybersecurity. He is driven by a passion for leveraging these skills to proactively track, analyze, and understand threat actor campaigns while gaining deeper insights into their evolving tactics and behaviors. | |||
| Automate to Defend: A Former FBI Agent's Ransomware Guide for CISOs | 22 Oct 2025 | 00:32:08 | |
Resources: https://linktr.ee/ReliaQuestShadowTalk Wondering what makes ransomware operations successful? Join host Kim along with intelligence analyst John & former FBI Special Agent Keith Mularski as they discuss:
Kim Bromley: Senior Cyber Threat Intelligence Analyst on the ReliaQuest Threat Research Team. She joined ReliaQuest in June 2020 following a 10-year career in UK law enforcement, and has acted as host since 2024. Kim brings a wealth of experience in threat intelligence and law enforcement tactics, providing unique insights. John Dilgen: Cyber Threat Intelligence Analyst at ReliaQuest, where he specializes in researching cyber threats impacting ReliaQuest customers. With a strong technical background, he previously served as an Incident Response Analyst and Trainer at ReliaQuest. Keith Mularski is the Chief Global Ambassador at Qintel, where he leads global engagement and represents the company’s intelligence mission across governments, industry, and cybersecurity communities worldwide. Before joining Qintel, Keith led the Cyber Threat Management group at Ernst & Young, advising Fortune 100 companies on proactive defense and intelligence strategies. He also served more than 20 years as an FBI Special Agent, leading groundbreaking cybercrime investigations and pioneering collaboration between law enforcement and the private sector. His undercover work has been featured in the books Kingpin and DarkMarket. Keith is also co-host of the podcast Only Malware in the Building, where he explores the stories behind cybercrime and threat intelligence. | |||
| Is Your Software a Secret Backdoor? Flax Typhoon's Latest Campaign Unwrapped | 15 Oct 2025 | 00:22:21 | |
Resources: https://linktr.ee/ReliaQuestShadowTalk How long could Flax Typhoon nestle silently in your networks? Join host Kim along with intelligence analysts John & Joey as they discuss:
Kim Bromley: Senior Cyber Threat Intelligence Analyst on the ReliaQuest Threat Research Team. She joined ReliaQuest in June 2020 following a 10-year career in UK law enforcement, and has acted as host since 2024. Kim brings a wealth of experience in threat intelligence and law enforcement tactics, providing unique insights. John Dilgen: Cyber Threat Intelligence Analyst at ReliaQuest, where he specializes in researching cyber threats impacting ReliaQuest customers. With a strong technical background, he previously served as an Incident Response Analyst and Trainer at ReliaQuest. Joseph Keyes: Cyber Threat Intelligence Analyst at ReliaQuest, specializing in technical cyber threat research. With his prior role as a Cyber Security Analyst, he has gained years of experience in triaging and responding to active threats using GreyMatter's various tools. Joseph is skilled in intrusion response, threat actor profiling, OSINT across the clear and dark web, and analyzing adversarial TTPs. | |||
| Cl0p's Latest Heist: Exploiting Oracle's Critical Vulnerability | 08 Oct 2025 | 00:35:08 | |
Resources: https://linktr.ee/ReliaQuestShadowTalk Join host Kim along with Intelligence Analyst John and Threat Detection Engineer Marken as they discuss:
Kim Bromley: Senior Cyber Threat Intelligence Analyst on the ReliaQuest Threat Research Team. She joined ReliaQuest in June 2020 following a 10-year career in UK law enforcement, and has acted as host since 2024. Kim brings a wealth of experience in threat intelligence and law enforcement tactics, providing unique insights. John Dilgen: Cyber Threat Intelligence Analyst at ReliaQuest, where he specializes in researching cyber threats impacting ReliaQuest customers. With a strong technical background, he previously served as an Incident Response Analyst and Trainer at ReliaQuest. Marken Teder: Threat Detection Engineer at ReliaQuest, with a total of 7 years at the company. A native Estonian, he has previously worked as an Incident Response Analyst, Content Developer, and Security Architect. Marken's extensive experience in detection and response brings a robust technical perspective to discussions. | |||
| Should Governments Hoard Zero Days? Analyzing Brickstorm Malware and Storm-1849 | 01 Oct 2025 | 00:26:29 | |
Resources: https://linktr.ee/ReliaQuestShadowTalk Join host Joey along with intelligence analysts Alex and Hayden as they discuss:
Joseph Keyes: Cyber Threat Intelligence Analyst at ReliaQuest, specializing in technical cyber threat research. With his prior role as a Cyber Security Analyst, he has gained years of experience in triaging and responding to active threats using GreyMatter's various tools. Joseph is skilled in intrusion response, threat actor profiling, OSINT across the clear and dark web, and analyzing adversarial TTPs. Hayden Evans: Cyber Threat Intelligence Analyst at ReliaQuest. He has experience in the F3EAD lifecycle and analyzing adversaries' TTPs to operationalize this information. He is also experienced with intrusion response, OSINT investigations, and offensive security. Alexander Capraro: Cyber Threat Intelligence Analyst at ReliaQuest with over five years of experience in cybersecurity. With his prior experience as a Security Analyst, he specializes in incident response, malware analysis and campaign tracking, and OSINT investigations. | |||