ShadowTalk: Powered by ReliaQuest - podcast cover

ShadowTalk: Powered by ReliaQuest

ReliaQuestreliaquest.com

Want to hear what industry experts really think about the cyber threats they face? ShadowTalk is a weekly cybersecurity podcast, made by practitioners for practitioners, featuring analytical insights on the latest cybersecurity news and threat research.

Threat Intelligence Analyst John Dilgen brings extensive expertise in cyber threat intelligence and incident response, specializing in researching threats impacting ReliaQuest customers. John and his guests provide practical perspectives on the week’s top cybersecurity news and share knowledge and best practices to help businesses mitigate the most pertinent cyber threats. 

 

With over 1,000 customers worldwide and 1,200 teammates across six global operating centers, ReliaQuest delivers security outcomes for the most trusted enterprise brands in the world. Learn more at www.reliaquest.com.

Last refreshed:
Follow this podcast in the Metacast mobile app to refresh it and see new episodes.
Download Metacast podcast app
Podcasts are better in Metacast mobile app
Don't just listen to podcasts. Learn from them with transcripts, summaries, and chapters for every episode. Skim, search, and bookmark insights. Learn more

Episodes

Weekly: CitrixBleed, Taking a Proactive Approach to IR, BiBi wiper targets Israeli Organizations

In this episode of ShadowTalk, host Chris, along with Kim, discuss the latest news in cyber security and threat research. Topics this week include: CitrixBleed vulnerability mass targeted by threat actors Taking the burden from incidents responders by taking proactive steps Hacktivists targeting Israeli organizations with "BiBi" data wiping malware Resources: https://www.reliaquest.com/blog/citrix-bleed-vulnerability-background-and-recommendations/...

Nov 15, 202330 min

Weekly: Apache ActiveMQ and Atlassian Confluence, SEC files charges, QR code phishing

In this episode of ShadowTalk, host Ivan Righi, along with ReliaQuest's CISO Rick Holland and Detection Researcher Marken Teder, discuss the latest news in cyber security and threat research. Topics this week include: Apache ActiveMQ vulnerability (CVE-2023-46604) exploited by ransomware gangs Discussion over charges filed by the US SEC against SolarWinds Active exploitation of a Critical Atlassian Confluence flaw (CVE-2023-22518) An overview of QR code phishing threats Resources: https://event....

Nov 08, 202336 min

Weekly: SolarWinds SEC Charges, Vulnerabilities Roundup, AI Executive Order

In this episode of ShadowTalk, host Kim, along with Caroline and Corey, discuss the latest news in cyber security and threat research. Topics this week include: The charges filed by the US SEC against SolarWinds A sneak-peak of the findings from our Vulnerabilities Roundup blog An overview of some vulnerabilities impacting users right now The Executive Order issued by the Biden administration on artificial intelligence.

Nov 02, 202333 min

Weekly: Q3 Ransomware Report, ServiceNow Vulnerability, Okta Incident

In this episode of ShadowTalk, Host Chris Morgan is joined by one of ReliaQuest's CISO's Rick Holland, Threat Hunter Brian Kelly and Threat Intelligence Analyst Ivan Righi to discuss the latest news in cyber security and threat research. Topics this week include: The findings of ReliaQuest's Quarterly Ransomware Report recapping Q3 2023 activity. ServiceNow vulnerability and what it means for you The latest on a security incident pertaining to authentication provider, Okta. Resources: https://ww...

Oct 26, 202335 min

Weekly: Hamas Cyber Threat Implications, Top Adversary Techniques, Qakbot

In this episode of ShadowTalk, host Chris Morgan, along with ReliaQuest CISO Rick Holland, James Xiang and Caroline Fenstermacher, discuss the latest news in cyber security and threat research. Topics this week include: Cyber threat implications from the Hamas - Israel Conflict Top Adversary Techniques: What We're Seeing Right Now Has Qakbot returned? Resources: https://www.reliaquest.com/blog/iranian-cyber-threats-practical-advice-for-security-professionals/...

Oct 13, 202336 min

Weekly: National Cyber Security Awareness Month (NCSAM), Progress FTP Server, RDP Sessions, IronNet

In this episode of ShadowTalk, host Chris Morgan, along with ReliaQuest CISO Rick Holland and Corey Carter discuss the latest news in cyber security and threat research. Topics this week include: 2023 National Cyber Security Awareness Month (NCSAM) Progress FTP Server The risk posed by open Remote Desktop Protocol (RDP) Sessions IronNet ceasure operations Resources: https://www.reliaquest.com/blog/cybersecurity-awareness-automation/ https://www.reliaquest.com/blog/israel-hamas-implications-for-c...

Oct 06, 202337 min

Weekly: Hunting for MFA bypass techniques, Libwebp Vuln exploited, VMWare ESXi

In this episode of ShadowTalk, host Chris, along with Gjergji and James, discuss the latest news in cyber security and threat research. Topics this week include: Hunting for MFA bypass techniques Exploitation of a Zero-day LibWebP Vulnerability Threat actors targeting VMWare ESXI Resources: https://www.reliaquest.com/blog/mfa-bypass-techniques/#:~:text=Attackers%20also%20bypass%20MFA%20by,for%20sale%20on%20cybercriminal%20platforms....

Sep 29, 202330 min

Weekly: MFA Bypass Techniques, Microsoft Data Leak, Latest ALPHV Attack

In this episode of ShadowTalk, host Kim, along with Caroline and Brian, discuss the latest news in cyber security and threat research. Topics this week include: A deep dive into popular MFA bypass techniques and how to mitigate them How a misconfigured SAS token led to a big Microsoft data breach The latest ALPHV ransomware attack Resources: https://www.reliaquest.com/blog/domain-redirection-attacks-wrong-turns-in-cyberspace/...

Sep 22, 202327 min

Weekly: Anonymous Sudan, Domain Redirection Attacks, UK Ransomware Report and Managed Engine Zero-Day Exploit

In this episode of ShadowTalk, host and ReliaQuest CISO Rick Holand and ReliaQuest Threat Research team members Corey Carter and Gjergji Paco discuss the latest news in cyber security and threat research. Topics this week include: A deep dive on domain redirection attacks New ransomware report from the UK government New Managed Engine zero-day exploited by multiple threat actors Anonymous Sudan Telegram bans and DDoS attacks. Resources: https://www.ncsc.gov.uk/whitepaper/ransomware-extortion-and...

Sep 14, 202335 min

Weekly: SocGhoulish deep dive, AI security concerns, LockBit vs. UK MOD

In this episode of ShadowTalk, host Roman, along with Corey and Ivan, discuss the latest news in cyber security and threat research. Topics this week include: A deep dive of malware loader SocGhoulish Artificial intelligence: implications, security concerns, and use by cybercriminals LockBit leaking top secret information from the UK’s Ministry of Defence Resources: https://www.reliaquest.com/blog/the-3-malware-loaders-behind-80-of-incidents https://www.reliaquest.com/blog/socgholish-fakeupdates...

Sep 08, 202334 min

Weekly: Qakbot Takedown, New Barracuda Zero-Day, Resurgence of Hacktivism

In this episode of ShadowTalk, host Chris Morgan, along with ReliaQuest CISO Rick Holland and Gjergji Paco, discuss the latest news in cyber security and threat research. Topics this week include: The FBI operation targeting Qakbot infrastructure Barracuda Zero-Day targeted by Peoples Republic of China (PRC) aligned actors The resurgence and future of Hacktivism

Sep 01, 202340 min

Weekly: Malware Loaders, Ransomware Runbooks, Generative AI and Barracuda ESG

In this episode of ShadowTalk, host Dean Murphy, along with one of ReliaQuest's CISO's Rick Holland and Threat Hunter Brian Kelly, discuss the latest news in cyber security and threat research. Topics this week include: Malware Loaders Ransomware Runbooks Generative AI Barracuda ESG - Zero-Day Resources: https://www.reliaquest.com/blog/lockbit-ransomware-2023/ https://analyst1.com/ransomware-diaries-volume-1/ https://www.bleepingcomputer.com/news/security/angry-conti-ransomware-affiliate-leaks-g...

Aug 25, 202328 min

Weekly: DefCon, Cl0p, Raccoon Stealer

In this episode of ShadowTalk, host Chris, along with one of Brandon and Gjergji, discuss the latest news in cyber security and threat research. Topics this week include: Recap of DefCon conference The latest updates regarding Clop's exploitation of MOVEit zero-day The return of the infamous Raccoon Stealer

Aug 18, 202332 min

Special: CISO Chat Live from BlackHat 2023

In this episode, one of ReliaQuest's CISO's Rick Holland and Chief Technology Officer Joe Partlow are joined by Freeport LNG CISO, Todd Beebe and Ciena CISO Ryan Hammer to discuss all things BlackHat 2023.

Aug 10, 202315 min

Weekly: Business Email Compromise (BEC), ReliaQuest Bi-Annual threat reports, influence of AI on the Cyber Threat Landscape

In this episode of ShadowTalk, host Chris, along with one of ReliaQuest's CISOs Rick, and James, discuss the latest news in cyber security and threat research. Topics this week include: Themes in recent Business Email Compromise (BEC) activity A breakdown of ReliaQuest research into threats facing the Professional, Scientific, and Technical Services (PSTS) sector The influence of AI on the cyber threat landscape ReliaQuest activities at BlackHat 2023 conference...

Aug 04, 202340 min

Weekly: What We're Seeing Right Now, Cl0p Cycle Continues, Ivanti Zero-Day, ALPHV API

In this episode of ShadowTalk, host Roman, along with Ivan and Brandon, discuss the latest news in cyber security and threat research. Topics this week include: Twitter becoming X security concerns Cl0p names 71 new victims ReliaQuest releases Q2 ransomware report Hackers target Norwegian government ministries with Ivanti zero-day exploit ALPHV ransomware group creates API key for its data leak site Resources: https://www.bleepingcomputer.com/news/security/norway-says-ivanti-zero-day-was-used-to...

Jul 28, 202331 min

Weekly: What We're Seeing Right Now, Cl0p Update, WormGPT

In this episode of ShadowTalk, host Chris, along with Brian and James, discuss the latest news in cyber security and threat research. Topics this week include: ReliaQuest research into common attacker techniques An update on Clop's exploitation of the MOVEit vulnerability ChatGPT rival with ‘no ethical boundaries’ sold on dark web Resources: https://www.reliaquest.com/blog/top-adversary-techniques-july-2023/ https://www.reliaquest.com/blog/clop-leaks-first-victims/ https://www.zdnet.com/article/...

Jul 21, 202322 min

Weekly: Microsoft Cloud Breach, Strava App, Cl0p Update and Remote Management Monitoring

In this episode of ShadowTalk, host Dean Murphy, one of ReliaQuests CISO's Rick Holland and threat research teamers Colin Ferris and Gjergji Paco discuss the latest news in cyber security and threat research. Topics this week include: Chinese hackers breach Microsoft Cloud Strava App – Tracked and Killed Cl0p Update Remote Monitoring and Management Software – RMM Resources: https://www.cnn.com/2023/07/11/europe/russian-submarine-commander-killed-krasnador-intl/index.html https://www.telegraph.co...

Jul 14, 202339 min

Weekly: Defense Evasion via Virtualization, LockBit target TSMC, CISA Identify New Exploited Vulnerabilities

In this episode of ShadowTalk, host Chris Morgan, along with Corey Carter, Jonny Elrod, Gjergji Paco, and one of ReliaQuests CISO's Rick Holland, discuss the latest news in cyber security and threat research. Topics this week include: Threat actors obfuscating activity through virtualization LockBit claim to have impacted Taiwanese semiconductor giant TSMC CISA identify new exploited vulnerabilities New critical vulnerability impacting Fortinet, FortiOS and FortiProxy SSL-VPN appliances Resource...

Jul 07, 202333 min

Weekly: Legal Developments, New APT29 Campaign and ReliaQuest's Annual Threat Report

In this episode of ShadowTalk, host Stefano, along with Kim Bromley, and one of ReliaQuests CISO's Rick Holland, discuss the latest news in cyber security and threat research. Topics this week include: The SEC reportedly charging SolarWinds executives APT29 hunting for credentials Our new, shiny Annual Threat Report Resources: https://www.reuters.com/technology/solarwinds-executives-receive-wells-notice-us-sec-2023-06-23/ https://www.scmagazine.com/brief/identity-and-access/apt29-intensifies-cre...

Jun 30, 202328 min

Weekly: Cl0p update, Killnet target European financial institutions, closed sources findings

In this episode of ShadowTalk, host Chris, along with Dani, and one of ReliaQuests CISO's Rick Holland, discuss the latest news in cyber security and threat research. Topics this week include: The latest updates related to Cl0p's exploitation of MOVEit zero-day Killnet targeting European financial institutions Insights drawn from our closed sources team The team's observations on this years InfoSec conference Resources: https://www.reliaquest.com/blog/clop-leaks-first-victims/ https://techmonito...

Jun 23, 202342 min

Weekly: Cl0p releases company names, Gootloader, new Fortinet RCE, Ukrainians hackers take down Infotel.

In this episode of ShadowTalk, host Chris, along with Colin and Caroline, discuss the latest news in cyber security and threat research. Topics this week include: The latest updates related to Clop's exploitation of MOVEit zero-day An overview of the Gootloader initial access malware Fortinet RCE CVE-2023-27997 Ukraine's Cyber Anarchy Squad take down Infotel Resources: https://www.reliaquest.com/blog/clop-leaks-first-victims/ https://www.scmagazine.com/news/device-security/fortinet-patches-criti...

Jun 19, 202333 min

Weekly: MOVEit Zero-day and Cl0p attribution, Infostealing ecosystem, DBIR 2023 Report

In this episode of ShadowTalk, host Stefano, along with Rick, Dean, and Ivan, discuss the latest news in cyber security and threat research. Topics this week include: What you need to know on the MOVEit Zero-day vulnerability and the latest Cl0p updates Infostealers ecosystem: most common malware, impact, and mitigation strategies Key insights from the latest Verizon's DBIR issue Resources: https://www.reliaquest.com/blog/moveit-vulnerability-update-clop-claims-responsibility/ https://www.verizo...

Jun 09, 202332 min

Weekly: MOVEit Zero-day, RaidForums Breach, Buhti Ransomware

In this episode of ShadowTalk, host Chris, along with Gjergji and Ivan, discuss the latest news in cyber security and threat research. Topics this week include: What you need to know on the MOVEit Zero-day vulnerability RaidForums user's data breached The Buhti ransomware taking a unique approach to targeting victims Resources: https://www.reliaquest.com/blog/moveit-transfer-zero-day/ https://www.bleepingcomputer.com/news/security/new-buhti-ransomware-gang-uses-leaked-windows-linux-encryptors/ h...

Jun 02, 202318 min

Weekly: GootLoader, Intrusion Truth, Volt Typhoon, and Exponent conference debrief

Summary: In this episode of ShadowTalk, host Stefano, along with Kim, Rick, and Dean, discuss the latest news in cyber security and threat research. Topics this week include: An investigation into the GootLoader malware The latest operation from hacktivist group Intrusion Truth A cyber espionage campaign conduct by Volt Typhoon RQ Exponent conference debrief Resources: https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-144a https://www.washingtonpost.com/politics/2023/05/15/they-dox-...

May 26, 202330 min

Weekly: SocGholish, Cactus Ransomware, Greatness Phishing-as-a-service

In this episode of ShadowTalk, host Chris Morgan , along with Caroline Fenstermacher and Gjergji Paco, discuss the latest news in cyber security and threat research. Topics this week include: Revisiting the SocGholish malware distribution framework Getting pricked by the Cactus ransomware Greatness Phishing-as-a-service Resources: https://www.reliaquest.com/blog/socgholish-fakeupdates/ https://thehackernews.com/2023/05/new-ransomware-strain-cactus-exploits.html https://www.bleepingcomputer.com/n...

May 19, 202331 min

Weekly: Snake malware takedown, Kubernetes hunts, and Caffeine Phishing-as-a-Service

Summary: In this episode of ShadowTalk, host Stefano, along with Caroline and Colin, discuss the latest news in cyber security and threat research. Topics this week include: Five Eyes agencies takedown FSB-linked Snake malware Hunting Kubernetes for privilege escalation techniques Investigation offers insights into Caffeine PhaaS platform Resources: https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-129a https://www.paloaltonetworks.com/apps/pan/public/downloadResource?pagePath=/cont...

May 12, 202337 min

Weekly: ReliaQuest Threat Management, ALPHV, Veeam Vulnerability Exploited

In this episode of ShadowTalk, host Chris Morgan is joined by Corey Carter and Ivan Righi to discuss: A day in the life of a Threat Engineer at ReliaQuest ALPHV leaking internal comm's related to victims incident response High Severity vulnerability affecting Veeam back servers exploited in the wild (CVE-2023-27532)

May 05, 202326 min
Hosted on Buzzsprout
For the best experience, listen in Metacast app for iOS or Android