ShadowTalk: Powered by ReliaQuest
ReliaQuest
0
ShadowTalk is a weekly cybersecurity podcast produced by ReliaQuest, aimed at security practitioners. Hosted by threat intelligence analyst John Dilgen, each episode breaks down the latest cybersecurity news and threat research with input from industry guests. The show focuses on practical analysis of emerging threats and the tactics, techniques and procedures that affect businesses. Listeners get best practices and expert perspectives on how to mitigate the most pressing cyber risks.
Epizodai
-
Fake NDAs, Real Money: Inside the M&A Social Engineering Playbook 23.09.2026 28minIn this episode, we examine the Phantom Deal campaign, in which threat actors used publicly available details about companies’ acquisition histories, subsidiaries, executives, and employees to create convincing fake M&A scenarios. The goal: persuade employees to initiate large financial transfers while keeping conversations off corporate communication channels. We also cover a recent series of zero-day disclosures affecting major endpoint-security and Windows products. These vulnerabiliti... -
From Vulnerability Research to Domain Admin in Minutes 16.09.2026 31minAI is changing the economics of cyberattacks. In this episode, we examine how a suspected threat actor used AI agents to accelerate PaperCut vulnerability research, exploit development, target identification, and post-compromise activity—moving from initial access to domain administrator access in as little as seven minutes. We also explore recent reporting on large-scale AI-model distillation campaigns by China-based companies and what the increasing availability of frontier-level AI capabil... -
One Empty Field: The Email Security Bypass Letting Attackers Impersonate Your Executives 09.09.2026 29minOrganizations rely on Microsoft 365's RejectDirectSend control to block internal email spoofing—but a structural gap lets attackers walk right past it. With nothing more than a basic Python script and an empty envelope sender, threat actors are impersonating executives, IT support, and finance teams to launch Business Email Compromise, payment fraud, and follow-on account takeover. Join hosts Alexandra Moore and John Dilgen as they discuss: How an empty email header field bypasses RejectDirec... -
From Data Dumps to Critical Findings: The New Era of Data Extortion 02.09.2026 28minThreat actors do not see old email archives, forgotten shared drives, and outdated CRM exports as clutter. They see them as searchable inventory. With AI-assisted analysis, attackers can rapidly identify sensitive communications, regulatory exposure, customer relationships, and credentials buried in stolen data. Join hosts John Dilgen and Brandon Tirado as they discuss: Why data theft has become a central component of modern extortion operationsHow AI and automation are helping attackers anal... -
Vishing at Scale: Inside the Criminal SaaS Platform Enabling Account Takeover 26.08.2026 31minWhat if a threat actor already knew your name, your job title, your manager's name, and your direct number before they ever picked up the phone? That's not a hypothetical — that's Work Panel. A new report gave us a rare inside look at the criminal SaaS platform enabling vishing campaigns at scale, and the findings are a wake-up call. Join hosts John Dilgen and Alexandra Moore as they break down: ✅ How Work Panel packages phishing infrastructure, team management, and real-time credentia... -
Nation-State Actors: Iran’s PLC Attacks, Russia’s Zero-Click Email Exploit, and North Korea’s Fake Employees 19.08.2026 27minThree nation-states. Three distinct playbooks. Iranian actors are targeting internet-exposed industrial controllers and disabling critical safety systems. A Russian threat group built a zero-click email exploit that steals 90 days of inbox data the moment a user views a message. And North Korean operatives are applying for software-development jobs at Western companies—and getting hired. Join hosts John Dilgen and Tehman Tariq as they break down: ✅ How Iranian actors manipulate PLC safety log... -
When AI Escapes the Lab: The Hugging Face Breach, PyPI Malware, and What It Means for Defenders 12.08.2026 23minFully autonomous attacks are here. AI agents escape a test environment, exploit zero-days, coordinate through shared infrastructure, and breach a production company—generating more than 17,000 security events along the way. Elsewhere, another model autonomously publishes malware to PyPI, while AI agents target real open-source developers with tailored social engineering. Join hosts John Dilgen and Tehman Tariq as they break down: ✅ How AI agents escaped containment and compromised Huggi... -
The Gentlemen, Deadlock, and Clop: The Groups Driving Ransomware & Extortion in 2026 05.08.2026 36minAn affiliate receives a ready-made intrusion kit — pre-compromised targets, an EDR killer, and a full deployment workflow included. No building from scratch. No long ramp-up. Just deploy, observe, and iterate. That's the future of ransomware; it's how the new number-one group operated in Q2 2026. And it's just one of three stories reshaping the extortion landscape right now. Join hosts Brandon Tirado and John Dilgen as they break down: How The Gentlemen's pre-packaged affiliate kit drove 580%... -
Compromised Hotel Gateways, Fake Microsoft Domains, and the APT28-Adjacent Campaign That Bypasses MFA Without a Phishing Click 29.07.2026 31minAn employee connects to hotel Wi-Fi, receives a familiar Microsoft 365 sign-in prompt, and authenticates. No phishing email. No malicious link. No suspicious attachment. Yet an attacker walks away with a valid, MFA-satisfied session token. Join hosts Alexandra Moore and John Dilgen as they break down: How compromised hotel and conference-center Wi-Fi gateways silently redirect Microsoft authentication trafficWhy hardcoded DNS, opportunistic encrypted DNS, and MFA may not stop the attack... -
The Largest Patch Tuesday Ever: 622 CVEs, a 1,380% Phishing Surge, and the Two-Front War on Initial Access 22.07.2026 28minDefenders aren't losing ground on one front, they're losing it on two at once. The largest Patch Tuesday in history just dropped alongside a 1,380% surge in phishing, and threat actors aren't waiting for you to catch up. Join hosts Alexandra Moore and John Dilgen as they break down: How new extortion group Helix and ClickFix are weaponizing identity compromise at scale Why 622 vulnerabilities in a single week signals a permanent shift in the discovery ratePractical defenses for bot... -
FortiBleed, 70,000 Compromised Devices, and the Credential Economy Powering Every Breach 15.07.2026 22minWhen a 20-person team using AI, automated tools, and a list of default credentials compromised 70,000 devices across 194 countries they exposed how mature the criminal market behind credential theft has become. Initial access brokers are now packaging pre-validated enterprise access for an average of $113,000, and the window from information stealer infection to ransomware deployment is just seven days. Join hosts Tehman Tariq and John Dilgen as they break down: The mechanics behind FortiBlee... -
Inside Conti's Leaked Chats: 300,000 Messages, a Criminal Empire, and the Ransomware Playbook Still Running Today 08.07.2026 42minWhen 300,000 internal messages from the world's most prolific ransomware gang were leaked, they exposed more then a shadowy underground network, a full company. HR departments. Conti operated with the structure of a mid-sized software firm, and that changes how defenders need to think about the ransomware landscape today. Join host John and special guest Geoff White, journalist and author of Rinsed, as they discuss: How Conti's internal org chart compares to a legitimate software companyThe h... -
How Hackers Are Using AI Right Now: Faster Attacks, Smarter Malware, and a New Arms Race 01.07.2026 25minAI is not replacing threat actors, instead it is making them faster, cheaper, and harder to stop. From AI powered phishing campaigns generating thousands of pages simultaneously, to a newly discovered macOS implant called Gaslight that injects fabricated system error messages into AI powered triage pipelines, the arms race between attackers and defenders is accelerating. The question is not whether AI is being used against your organization. It is whether your defenses are keeping pace. Join ... -
Klue, Kali365, OAuth: When the Front Door Is a Trusted Integration 24.06.2026 28minIn the Klue compromises threat actors walked in through a trusted integration, using legitimate credentials to quietly siphon Salesforce CRM data at scale. The challenge isn't just responding to Klue. It's recognizing that every OAuth-connected integration in your environment is part of your attack surface. Join hosts Alexandra and John as they discuss: How compromised Klue integrations were leveraged to exfiltrate Salesforce CRM dataAttribution and what it signals about the evolving data ext... -
ShinyHunters' Expanding Toolkit: Oracle PeopleSoft Zero-Day Exploitation and the BreachForums Defense Gaps 17.06.2026 19minShinyHunters dominated headlines this week: a zero-day, a BreachForums listing, and unverified claims all hitting at once. The problem isn't just keeping up with the volume. It's knowing which of it is real, which is noise, and what your team actually needs to act on. Join hosts Tehman and John as they discuss: ShinyHunters zero-day exploitation of CVE-2026-35273Why a BreachForums listing extends the threat well beyond the initial compromiseWhat proactive, resource-development-stage detection... -
China-Linked Cyber Espionage: How OP-512 Exploited Legacy IIS Servers and Evaded Detection 10.06.2026 23minYour team built defenses around known China-linked clusters. The file hashes are tracked. The behavioral patterns are documented. What those weren't built to catch is a new cluster that studied those exact defenses and engineered around them. A China-linked attacker compromised an internet-facing IIS server, maintained access for over 75 days, and came back on fresh infrastructure. With four China-linked clusters converging on the same legacy IIS stack in twelve months, defenders building det... -
SonicWall, MFA Bypass, IABs: Why Patched Devices Are Still Handing Attackers Initial Access 03.06.2026 20minYour team patches the device. The firmware version matches the advisory. The ticket closes. The device comes off the remediation queue. What your workflow never tracked is that the advisory also required six manual LDAP configuration steps — and without them, the authentication bypass still works. An initial access broker authenticated through the VPN, reached a domain-joined file server, and was gone in under 40 minutes. Your dashboard still showed a clean queue. With initial access brokers ... -
Device Code, OAuth, PhaaS: How Session Token Theft is Breaking the Phishing Playbook 27.05.2026 29minYour user clicked a link, landed on a real Microsoft login page, typed their password, completed MFA, and walked away thinking nothing happened. Somewhere across the internet, an attacker's device just received an authenticated session token. The password is irrelevant. The MFA prompt already fired and passed. With PhaaS platforms now converging on token-theft tradecraft and post-compromise automation executing in seconds, defenders are racing a scripted attacker with a manual playbook. Join ... -
SQLite, Mistral, OpenAI: How AI Attacks Are Reshaping the Attack Surface 20.05.2026 19minWhat happens when an AI agent uncovers a zero-day in hours instead of weeks, and state-backed groups are already operationalizing the same tools? With self-hosted AI infrastructure sprawling outside asset registers and supply chain worms reaching inside AI vendors themselves, defenders need a new operating model. Join hosts Tehman and John as they discuss: How an AI agent surfaced a memory-safety zero-day in SQLiteHow Mini Shai-Hulud reached Mistral AI and OpenAI devicesWhy the intel-to... -
Canvas, Trellix, Mini Shai-Hulud: How Defenders Respond When Supply Chain Attacks Become Weekly 14.05.2026 31minWhat's driving the surge in weekly supply chain attacks, and why does the real defender problem start after the supplier gets hit? With 275 million records exposed and 8,809 institutions caught in the downstream fallout, organizations need a new playbook. Join hosts Alexandra and John as they discuss: How ShinyHunters abused admin sessionsRansomHouse's hypervisor-focused automationHow Mini Shai-Hulud compromised 170+ npm packages Two questions your organization should be asking right now...
Populiari šalyje
Ši tinklalaidė taip pat patenka į šių šalių tinklalaidžių topus.