Adversary Universe Podcast

Adversary Universe Podcast

CrowdStrike
Maa Yhdysvallat
Kieli EN
Jaksot 77
Viimeisin 10.09.2026

Modern adversaries are relentless. Today’s threat actors target organizations around the world with sophisticated cyberattacks. Who are they? What are they after? And most importantly, how can you defend against them? Welcome to the Adversary Universe podcast, where CrowdStrike answers all of these questions — and more. Join our hosts, a pioneer in adversary intelligence and a specialist in cybersecurity technology, as they unmask the threat actors targeting your organization.

Jaksot

  • Preparing for an AI-Powered Future with Amazon CSO Steve Schmidt 10.09.2026 37min
    Steve Schmidt, SVP and CSO at Amazon, sees firsthand how both defenders and adversaries are using AI to their advantage. In this episode, he joins Adam and Cristian to discuss modern AI models, evolving adversary behavior, and how Amazon is responding to shifts in the threat landscape.“The big change we’ve seen recently is the ability of models to chain things together to produce something interesting,” Steve says. As AI models grow more adept at automatically chaining and acting, he adds, the time to respond has dramatically decreased.Defenders must now measure and respond in seconds or minutes, when they used to have hours or days. In using AI to fight AI-driven attacks, they must also consider which AI models they’re using. Using the right model is essential. If the business is building defenses for Mythos or Fable, and the adversary is using a different technology, the threat model changes.While adversarial use of AI is a primary concern, right alongside it is employees’ use of AI. As Steve puts it, to build a good AI governance program, defenders need strong identity governance and data governance programs. The identity component is key. Many organizations over-permission agents; others are so restrictive they defeat the purpose of having agents at all.How did Amazon handle this? Steve shares how the company built its own authentication framework that treats agents as a third type of identity. The agent temporarily inherits permissions through session-based delegation from the human who deployed it; it can only access what that person can access. It can’t do what they can’t do, even if a malicious prompt tries to trick it.Tune in to hear more details about AI-driven defense, and the evolution of AI-powered offense, in this episode of the Adversary Universe podcast.
  • AI as a Weapon, Target, and Enterprise Reality with CoreWeave’s Natasha Eastman 13.08.2026 42min
    “What are these AI systems attached to that make them such a huge risk?”“Everything.” Today, the Adversary Universe podcast welcomes Natasha Eastman, head of threat intelligence at CoreWeave, to share her perspective on how AI is used in the modern enterprise, the infrastructure needed to support it, and how she sees adversaries both using and attacking it.AI hasn’t necessarily given adversaries wholly new capabilities, Natasha explains. It enables them to do things faster, more capably, and with a lower barrier to entry. AI is seen in phishing scams, recon, coding and tooling support, fraud, and language and persona operations. It’s allowing threat actors to refine their content and make phishing even harder to detect. When it comes to attacks on AI, supply chain compromise and identity targeting are top of mind. Depending on how agents are configured and who configured them, they can have a phenomenal amount of access to internal and external resources. An attacker who gains control of an employee or agent identity could have unrestricted access to company systems and resources without the right guardrails in place. Our hosts and guest agree: It’s the new insider risk. “Everyone’s infrastructure that has access to AI capability is a target,” Natasha says.Tune in to hear Adam, Cristian, and Natasha pool their observations on AI threats, share what concerns them most, and offer their advice on what makes a strong AI governance program.
  • Unpacking the CrowdStrike 2026 Threat Hunting Report with CrowdStrike’s Katie Blankenship 03.08.2026 32min
    The CrowdStrike 2026 Threat Hunting Report is now live! The report sheds light on how our threat hunters and analysts hunt and defend against the world’s most sophisticated adversaries. It’s packed with stories from the front lines and trends that define the modern threat landscape.Joining Adam to dig into its findings is Katie Blankenship, Sr. Director of the Global Threat Analysis Cell for the CrowdStrike Counter Adversary Operations team. Katie, who leads the charge for our major intelligence reports, explains the herculean effort that goes into distilling a year’s worth of events into a single report. The CrowdStrike 2026 Threat Hunting Report is the product of seven trillion events analyzed, 14 million daily detection leads, and 36,000 annual customer alerts and notifications.So what did they tell us? These are some key takeaways covered in this episode:The window between vulnerability disclosure and exploitation is collapsing. From January through June 2026, 88% of CrowdStrike-observed exploitation of vulnerabilities with a public proof of concept (PoC) was conducted within 48 hours of the PoC’s release. China-nexus adversaries VAULT PANDA and GENESIS PANDA, both highly active in the last six months, are monitoring vulnerability disclosures so they can quickly weaponize them.Adversaries are targeting the developer ecosystem. Software supply chain attacks aren’t new, but adversaries are seeing opportunities to exploit trust relationships in this pipeline. ALTERED SPIDER is one of them — this adversary compromised 300+ software dependencies in one day, harvested credentials, and pivoted into cloud environments.Technology and finance are in the crosshairs. Technology was the most targeted sector for the ninth year running. DPRK-nexus adversary FAMOUS CHOLLIMA’s operations accounted for 55% of all state-sponsored intrusions targeting this sector. The financial services sector saw an 11% year-over-year increase in targeting, with FAMOUS CHOLLIMA driving activity there as well.Tune in to hear Adam and Katie discuss the CrowdStrike 2026 Threat Hunting Report’s most interesting stories, stats, and adversaries in an episode that Adam calls “the podcast for those who didn’t want to read the 48-page report.”Methodology & Source: All information provided is based on the CrowdStrike Counter Adversary Operations team’s proprietary threat intelligence gathered between July 1, 2025, and June 30, 2026. Stats may include data from the entire period surveyed or excerpts of data from specific date ranges within the period.
  • SaaS Security Threats to Worry About, with Salesforce’s Kelly McCracken 09.07.2026 36min
    Kelly McCracken, SVP of the Cyber Security Operations Center at Salesforce, leads one of the most complex and high-scale cyber operation environments on the planet. Today, she joins Adam and Cristian to discuss how adversaries are targeting SaaS vendors, the most underappreciated SaaS misconfigurations, and what the future of the shared responsibility model looks like.SaaS is a continuously growing target, but who is taking aim? eCrime adversaries such as SNARKY SPIDER and CORDIAL SPIDER are ones to watch, Adam says. They take advantage of poorly secured identities that make for lucrative targets. If a threat actor can log in as a legitimate user and gain access to a SaaS environment, they can reach any range of applications with poor security configurations — and exfiltrate their sensitive data.The shared responsibility model is essential to defense. Businesses must understand what their vendors are responsible for securing and what they’re responsible for securing. A lack of configurations and policies opens the door to both external adversaries and insider threats.“I feel like most security teams are flying blind when it comes to what’s going on with some of the most precious data for their company,” Kelly says.Tune in for a deep-dive conversation on one of the most prominent threats facing businesses today and stick around to hear about Cristian’s latest culinary fail and Kelly’s elite Latin skills.
  • Examining the Glassworm Takeover with Tillmann "Bot Slayer" Werner 25.06.2026 38min
    He’s back, and he’s ready to talk botnet takeovers.Tillmann Werner, VP of Intelligence Production at CrowdStrike, returns to the podcast to discuss CrowdStrike’s coordinated takeover of the Glassworm botnet. Glassworm was a global threat targeting software developers through the open-source supply chain. This infection vector stood out — open-source ecosystems are based on trust, and adversaries are learning they can reach a vast pool of victims by compromising the supply chain. Some open-source libraries get 100 million downloads per week.Glassworm was described as an “unkillable” botnet. Resilience was built into its design, which relied on four different command-and-control channels. This made the takeover complicated because a botnet can’t be taken over until all command-and-control mechanisms are suppressed.“Once it’s down, you gotta make sure it’s down,” said Adam, who calls Tillmann the “bot slayer.”In this episode, they get into the details: what Glassworm was after, how its unknown operators strengthened its infrastructure, and the planning and execution behind the takeover. Tillmann and his team facilitated the process by conducting extensive technical analysis, understanding Glassworm’s evolution, and spotting the opportunity to disrupt it. They worked with partners across the private and public sectors, as well as internally at CrowdStrike, to do it safely and avoid disrupting critical systems.Come for the behind-the-scenes details, and stay for the debate around baking the perfect pizza in this episode of the Adversary Universe podcast. Learn more in our blog: https://www.crowdstrike.com/en-us/blog/inside-crowdstrike-takedown-of-a-developer-targeting-botnet/.
  • China Targets Technology to Steal AI Capabilities It Can’t Build 09.06.2026 43min
    The technology sector is the most targeted in the world by eCrime and state-sponsored threat actors. Between April 1, 2025, and March 31, 2026, China-nexus adversaries drove more than 58% of state-sponsored interactive intrusions against the sector, creating the greatest intelligence collection threat to tech companies.These threat actors are escalating espionage against tech businesses to steal the AI capabilities and intellectual property they can’t build fast enough on their own. Adversaries such as MURKY PANDA, MUSTANG PANDA, OVERCAST PANDA, SUNRISE PANDA, and WARP PANDA targeted the tech sector more than any other industry. And China isn’t alone — Democratic People’s Republic of Korea (DPRK) adversaries also have their sights set on tech.The CrowdStrike 2026 Technology Threat Landscape Report, now live, sheds light on how nation-state and eCrime adversaries are targeting this critical industry. From FAMOUS CHOLLIMA’s IT infiltration campaigns to eCrime adversaries accelerating extortion, there is a broad range of threats that tech organizations must prepare for.Modern tech companies are creating the world’s most valuable and targeted assets, and their cutting-edge innovations represent both competitive advantage and greater risk. Tune in to learn the report’s key takeaways and hear Adam and Cristian dive into the report’s findings.
  • Adversaries Follow the Money: The CrowdStrike 2026 Financial Services Threat Landscape Report 18.05.2026 30min
    The CrowdStrike 2026 Financial Services Threat Landscape report is now live! Adam and Cristian are here to break down the trends and techniques affecting an industry that has become a major target for adversaries.Financial services is the fourth most-targeted industry as of Q1 2026 and accounts for 12% of all observed adversary activity. eCrime adversaries target the industry for financial gain. MUTANT SPIDER, the most active eCrime threat in the past 12 months, is tied to several intrusions in which they sell access to ransomware groups. The Democratic People’s Republic of Korea set its sights on cryptocurrency and fintech entities to steal funds for its military programs.While financial gain may seem the obvious goal in targeting financial services, it’s not the only one. Nation-state adversaries in China, Iran, and Russia launched operations against the sector for intelligence collection. Hacktivists conducted DDoS campaigns and data breach operations, primarily driven by ideological conflicts. Even if you don’t work in the financial services sector, you most likely work with it — consumer banks, credit card companies, insurers, payment processors, and related businesses are all part of everyday business and personal life. Tune in to hear which adversaries are targeting them and why, which regions are in the crosshairs, and how companies should defend themselves. And stick around to hear about Adam’s foray into ice cream cakes.
  • The Partnerships Taking on AI Security: Daniel Bernard, CrowdStrike Chief Business Officer 07.05.2026 38min
    The previous episode of the Adversary Universe podcast explored the “vuln-pocalypse” and the implications of advanced AI models accelerating vulnerability discovery and exploitation. Now, we’re diving into how companies are working together to face these evolving security risks.CrowdStrike Chief Business Officer Daniel Bernard spends much of his time talking with partners and customers about how to address their growing concerns: Is their business protected? Do they know which vulnerabilities are in their environment? What do they do about them?In this episode, Daniel joins Adam and Cristian to discuss why it takes an ecosystem of partners to answer these questions and help each business evaluate risk. He sheds light on the newly expanded Project Quiltworks — CrowdStrike’s coalition for securing frontier AI risk — as well as Anthropic’s Project Glasswing and OpenAI’s Trusted Access for Cyber as initiatives the industry needs in this critical time.“It feels like right now we’re at this fever-pitch moment ... where we’re going to do more patching in the next 6-12 months than we’ve probably done in the last 6-12 years," he says in this episode.To handle this, partner efforts are picking up speed. The “digital line” to join the project is growing as organizations jump in to help with solving the new problems companies face. Tune in to hear the latest on Project Quiltworks, the issues coming up most in CISO conversations, and of course, everyone’s favorite bread of the moment in this episode of the Adversary Universe podcast.
  • The "Vuln-pocalypse" Looms: Are We Cooked? 23.04.2026 29min
    Many cybersecurity conversations of late are discussing the impending “vuln-pocalypse” — a term used to describe a scenario in which AI-powered tools are used to discover and exploit vulnerabilities faster than defenders can patch them.It’s a valid concern. Even without advanced AI algorithms, researchers can build tools to automate the vulnerability discovery process. Now, the rise of increasingly sophisticated AI models is rapidly expanding the volume of vulnerabilities defenders will need to handle. “I’ve been saying since November, we’re looking at three to nine months until a massive influx of zero-day vulnerabilities,” Adam says in this conversation. Which begs the question: Are we cooked? No, he says, but it’s getting hot in here. In this episode, Adam and Cristian explore the vuln-pocalypse from the defender's perspective. They dive into the economics of this shift and explain how organizations should approach their patching strategy going forward. This isn’t an “end of the world” problem, they say, but it will require a more thoughtful approach to which vulnerabilities are patched, how they’re patched, and when. Tune in for this timely conversation as adversaries and defenders alike explore the potential of AI.
  • Hunting Supply Chain Attacks with Jared Myers, Director, CrowdStrike OverWatch 09.04.2026 26min
    Supply chain attacks targeting AI have recently been making headlines — and keeping the CrowdStrike OverWatch team busy. Jared Myers, director of CrowdStrike OverWatch, joins Adam in this episode to discuss his team’s approach to detecting and responding to these attacks.When a supply chain attack uses a zero-day vulnerability to breach a target, it’s often the CVE that grabs attention. But the zero-day isn’t what CrowdStrike OverWatch is after, Jared says. It’s the follow-on tradecraft once the adversary is inside. He takes listeners behind the scenes of the team’s response to recent supply chain attacks, including the MOVEit attack of 2023 and the Axios supply chain incident of March 2026, to share the technical details of how the team learns and acts on information as attacks are unfolding.Identity is an essential component in supply chain attacks, Jared explains. Once an adversary is in, they’re looking for a user account to help them move laterally. He shares advice with listeners and key takeaways from the team’s identity threat hunting.CrowdStrike OverWatch is a 24/7/365 operation, with experts working around the clock across time zones with visibility into trillions of events per day. By the time an attack makes headlines, CrowdStrike OverWatch may have known about it for months.“We don’t ever stop looking; we don’t ever stop hunting,” says Jared.Notes:• Blog: STARDUST CHOLLIMA Likely Compromises Axios npm Package [https://www.crowdstrike.com/en-us/blog/stardust-chollima-likely-compromises-axios-npm-package/]• Blog: From Scanner to Stealer: Inside the trivy-action Supply Chain Compromise [https://www.crowdstrike.com/en-us/blog/from-scanner-to-stealer-inside-the-trivy-action-supply-chain-compromise/]
  • Breaking Down the New National Cybersecurity Strategy 10.03.2026 47min
    The Trump administration has released a national cybersecurity strategy that commits to strengthening defenses through six core pillars: employing more offensive cyber operations, streamlining regulations, modernizing and protecting federal networks, securing critical infrastructure, leading in new technologies, and developing talent. In this episode, Rob Sheldon, Sr. Director of Public Policy and Strategy at CrowdStrike, joins Adam and Cristian for a deep dive into three of the pillars that are top of mind for them: offensive cyber operations, updating federal systems, and protecting critical infrastructure. They discuss why these are difficult problems to solve and key considerations for how to approach them, including relevant threat activity and the involvement of the private sector.  Though they could have talked about this for hours, this is a busy team! Check out the full cybersecurity strategy text for more details. [https://www.whitehouse.gov/wp-content/uploads/2026/03/President-Trumps-Cyber-Strategy-for-America.pdf] Interested in government cybersecurity? Register here for Fal.Con Gov 2026, taking place March 18 in Washington, D.C. [https://www.crowdstrike.com/en-us/events/fal-con/gov/register/]
  • Speed, Stealth, and AI: The CrowdStrike 2026 Global Threat Report 24.02.2026 33min
    It’s that time of year: The CrowdStrike 2026 Global Threat Report is live, and Adam and Cristian are here to break down the key findings. This year’s report spotlights adversaries’ heightened speed, their evolving use of AI, an increase in activity from China and North Korea, and the growth of supply chain attacks, zero-day exploitation, and cloud targeting.For new listeners, the annual Global Threat Report delivers an analysis of the modern threat landscape based on CrowdStrike's frontline observations and real-world threat intelligence from the previous year.2026 was the year of the evasive adversary. As defenses get stronger, adversaries are focused on refining their techniques to target security blind spots and bypass detection. AI is helping them accelerate and find creative ways around defenses for hands-on-keyboard operations. In 2025, AI-enabled adversaries increased attacks by 89% year-over-year.The trend is poised to continue: “I don’t think AI is going to create the malware — I think AI is going to be the malware,” Adam said.But AI isn’t the only factor shaping the modern threat landscape. Below are a few key stats from the report:• The average eCrime breakout time fell to 29 minutes — a 65% increase in speed from 2024. The fastest breakout we observed occurred in just 27 seconds.• 82% of detections were malware-free, continuing a steady trend in recent years.• North Korea-nexus incidents jumped 130%, and FAMOUS CHOLLIMA's activity doubled compared to 2024.• We observed a 42% increase in vulnerabilities exploited prior to public disclosure and a 37% rise in cloud-conscious intrusions.Tune in to learn about these findings and more from the CrowdStrike 2026 Global Threat Report.
  • Interview with a Threat Hunter: Brody Nisbet, Sr. Director of CrowdStrike OverWatch 12.02.2026 39min
    Threat hunting is hard to define, but Brody Nisbet, Sr. Director of CrowdStrike OverWatch, breaks down the basics in an episode that starts with the CrowdStrike OverWatch mission and dives into his stories from the front lines of threat hunting.This team detects adversaries in customer environments before they can achieve their nefarious goals. “Our mission is to outcompete your adversary,” Brody says. His team notifies customers of adversary activity and provides them with the actionable intelligence required to protect themselves. A staggering amount of data goes into the CrowdStrike OverWatch team's process: 5.7 trillion events per day (65 million events per second). The team triages this data and “sorts the wheat from the chaff” to figure out what’s most important for each business.As you might imagine, this work leads to some fascinating findings and stories. Tune in to hear Adam, Cristian, and Brody chat about encounters with FAMOUS CHOLLIMA and OPERATOR PANDA — and a cold case centered around malware dubbed Fluffy Cannoli.
  • LABYRINTH CHOLLIMA Evolves into Three Adversaries 29.01.2026 32min
    LABYRINTH CHOLLIMA, which is among the most prolific DPRK-nexus adversaries that CrowdStrike tracks, has evolved into three separate threat actors: GOLDEN CHOLLIMA, PRESSURE CHOLLIMA, and LABYRINTH CHOLLIMA.Each adversary has specialized goals and tradecraft. While LABYRINTH CHOLLIMA continues to prioritize espionage and targets specific industries, GOLDEN CHOLLIMA and PRESSURE CHOLLIMA focus on cryptocurrency entities and stand out for the scale and scope of their operations. In this episode, Adam and Cristian explain when it became clear that one adversary had evolved into three and discuss how they differ — and, interestingly, what they still have in common. Despite operating independently, the three adversaries still share tools and infrastructure, a sign of coordination within the DPRK cyber ecosystem. To put this development into context, the hosts take us back to the early days of North Korea's cyber activity and trace the progression of the many nation-state threat actors operating on its behalf. Tune in to learn about a significant update for a prolific nation-state adversary.Learn more about:• The LABYRINTH CHOLLIMA evolution in our new blog post• Fal.Con Gov 2026 • CrowdTour 2026
  • Taking Down Cybercriminals with Shawn Henry, Former FBI Leader 15.01.2026 48min
    How do you take down a cybercriminal? Last month, we explored that question through the lens of Operation Endgame. Today, we ask Shawn Henry, former Executive Assistant Director of the FBI and current Executive Advisor to the Founder and CEO of CrowdStrike.In some ways, it’s similar to taking down criminals in the physical world. But the speed and scale of cybercrime operations exacerbate the challenge of stopping them. While infrastructure can be dismantled, the impact is now short-lived as adversaries pivot to other setups. While law enforcement considers how to replicate successful operations, cybercriminals are thinking about how they can adapt and stay ahead. For those pursuing adversaries, speed and scale are difficult to achieve. As Shawn explains, successful takedowns require collaboration among dozens of groups; among them law enforcement agencies, international partners, intelligence analysts, reverse engineers, prosecutors, and private sector organizations that have visibility into adversary infrastructure.“A takedown isn’t a single door-kick moment. It’s a monthslong choreography of legal process and infrastructure mapping and partner synchronization,” he says. Are there ways to accelerate the process? He has a few ideas. Tune in as Shawn joins Adam and Cristian to share a behind-the-scenes take on stopping cybercrime. Learn the key challenges law enforcement faces, how a takedown comes together, why arrests alone aren’t enough to stop adversaries, and where there is still an opportunity to have real impact.
  • 2025 Wrapped: Updates on This Year’s Hottest Topics 30.12.2025 36min
    This was a busy year for the Adversary Universe podcast. We covered the emergence of new adversaries, the weaponization of AI, critical CrowdStrike research, and how cyberattacks look in different regions of the world.To recap 2025, we’re revisiting the topics that resonated most with our listeners to share year-end updates. Adam and Cristian cover the I-Soon data leaks, evolution of China as a nation-state threat, re-emergence of SCATTERED SPIDER, and the latest in ransomware-as-a-service. Tune in to learn the factors that may shape Chinese cyber operations in 2026 and why SCATTERED SPIDER activity looks different now compared to its summer of cybercrime. As a bonus, Adam shares some of the latest eCrime stats his team is seeing as we close out 2025 and explains why he believes we’ll see “an explosion of zero-days” in the months ahead. The adversary never slows down — and neither do we. We look forward to bringing you more information on the newest cyber threats in 2026. For more information:• I-Soon episode: See You I-Soon: A Peek at China’s Offensive Cyber Operations• Blog post: Unveiling WARP PANDA, a New Sophisticated China-Nexus Adversary• Blog post: CrowdStrike Services Observes SCATTERED SPIDER Escalate Attacks Across Industries
  • Is This Endgame? How Takedowns Are Reshaping eCrime 18.12.2025 35min
    In November 2025, a major public-private sector collaboration took down three significant malware networks. Operation Endgame involved law enforcement agencies from six EU countries, Australia, Canada, the U.K., and the U.S., along with Europol and 30 private sector partners, including CrowdStrike. The dismantled infrastructure consisted of hundreds of thousands of infected computers containing several million stolen credentials. Operation Endgame was a critical disruption of adversary operations — but it wasn’t the first. Law enforcement has for years sought to take down adversary infrastructure and often partners with private sector organizations like CrowdStrike to inform their operations. By disrupting the tools and processes threat actors rely on, these takedowns raise the cost for adversaries and make it harder for them to operate. As Adam and Cristian discuss in this episode, takedowns require careful planning and constant innovation. Adversaries are always finding new techniques and tools, and law enforcement must do the same. While disruption may slow them down, threat actors are often quick to pivot and find new ways to achieve their goals. In this episode, we examine how law enforcement takedowns disrupt adversary operations, how adversaries respond, where the private sector provides support, and what this all means for organizations facing modern threats.
  • Defrosting Cybersecurity’s Cold Cases with CrowdStrike’s Tillmann Werner 04.12.2025 34min
    Not all cybercrimes are resolved. Some threat groups disappear completely, and some malware is never seen again. But sometimes, a long-dormant case is cracked open and elusive answers are found. Tillmann Werner, VP of Intelligence Production at CrowdStrike, has been a member of the CrowdStrike Intelligence team since 2012 and has analyzed many of these cold cases. In this episode, he joins Adam to chat about unresolved cyberattacks, the adversaries behind them, and cases that remained inactive for years before new technology or data allowed experts to close them. While it’s frustrating to close a file without success, Tillmann says, the evolution of technology and proliferation of data often help solve old cases that have collected dust. Tune in to hear Adam and Tillmann look back at decades-old eCrime and nation-state campaigns, some of which now have answers — and others that remain a mystery. 
  • Prompted to Fail: The Security Risks Lurking in DeepSeek-Generated Code 19.11.2025 37min
    CrowdStrike research into AI coding assistants reveals a new, subtle vulnerability surface: When DeepSeek-R1 receives prompts the Chinese Communist Party (CCP) likely considers politically sensitive, the likelihood of it producing code with severe security flaws increases by up to 50%. Stefan Stein, manager of the CrowdStrike Counter Adversary Operations Data Science team, joined Adam and Cristian for a live recording at Fal.Con 2025 to discuss how this project got started, the methodology behind the team’s research, and the significance of their findings. The research began with a simple question: What are the security risks of using DeepSeek-R1 as a coding assistant? AI coding assistants are commonly used and often have access to sensitive information. Any systemic issue can have a major and far-reaching impact.  It concluded with the discovery that the presence of certain trigger words — such as mentions of Falun Gong, Uyghurs, or Tibet — in DeepSeek-R1 prompts can have severe effects on the quality and security of the code it produces. Unlike most large language model (LLM) security research focused on jailbreaks or prompt injections, this work exposes subtle biases that can lead to real-world vulnerabilities in production systems. Tune in for a fascinating deep dive into how Stefan and his team explored the biases in DeepSeek-R1, the implications of this research, and what this means for organizations adopting AI. 
  • Extortion Rises and Nation-State Activity Intensifies: The CrowdStrike 2025 European Threat Landscape Report 06.11.2025 27min
    Europe is a prime target for global adversaries. There is a strong emphasis on eCrime across the region as well as a rise in hacktivism and espionage stemming from ongoing conflicts.The CrowdStrike 2025 European Threat Landscape Report breaks down these trends. In this episode, Adam and Cristian cover the highlights.They start with cybercrime, a major theme of the report. The five most targeted European nations were the U.K., Germany, Italy, France, and Spain, which also represent the region’s largest economies (excluding Russia). The most targeted sectors were manufacturing, professional services, technology, industrials and engineering, and retail. Adam explains how eCrime threat actors are looking for victims with a high need to stay operational.“With manufacturing, if they’re knocked offline because of ransomware, they can count the downtime in dollars and cents,” he shares as an example.On the nation-state front, Russia is top of mind. Since its invasion of Ukraine in 2022, many Russian threat actors who operated globally are more focused on Ukraine and areas related to the conflict. Adam and Cristian discuss reports of North Korean threat actors supporting the Russians with weapons and personnel, North Korea targeting Ukraine, and the tactics and techniques that stand out most. The European threat landscape is crowded and complex. Tune in to understand the key findings, and download the full report for more details. https://www.crowdstrike.com/en-us/resources/reports/2025-european-threat-landscape-report/

Suosittu maassa

Tämä podcast esiintyy myös näiden maiden podcast-listoilla.