Microsoft Threat Intelligence Podcast

Microsoft Threat Intelligence Podcast

By MicrosoftBusinessTechnology
Download on the App Store

Microsoft Threat Intelligence Podcast episodes

  • Inside this year’s Microsoft Digital Defense Report

    In this episode, host Elliot Volkman is joined by Chloe Messdaghi and Karen Frost for a behind-the-scenes look at Microsoft’s annual Digital Defense Report (MDDR). They explore how AI is reshaping the cybersecurity landscape by increasing the speed, scale, and automation of attacks while also giving defenders new tools to detect and respond to threats. The conversation covers AI agents, phishing and identity-based attacks, vulnerability management, security resilience, and the growing need for organizations to connect signals across their environments. Chloe and Karen also share practical priorities for CISOs and discuss what the rise of increasingly autonomous AI agents could mean for the future of cyber defense. 


    In this episode you’ll learn:      

    • AI is accelerating the speed and scale of cyber threats 

      • Identity protection and phishing-resistant MFA remain critical 

        • Defenders need AI to manage growing security signals and threats 


        • Some questions we ask:     

          • How can we keep up with vulnerabilities and determine which patches to prioritize? 

            • If you’re a CISO reading the report, what are the three biggest actions you should take? 

              • What does the research and threat intelligence tell us about the changing risk landscape? 

              • Resources:  

                • Read the report 

                  • Access the shorter summary 

                    • View Chloe Messdaghi on LinkedIn  

                      • View Elliot Volkman on LinkedIn  

                      •  

                        Related Microsoft Podcasts:                   

                        • The BlueHat Podcast 

                          • Uncovering Hidden Risks     

                          •  

                            Discover and follow other Microsoft podcasts at microsoft.com/podcasts  

                             

                            Get the latest threat intelligence insights and guidance at Microsoft Security Insider 

                             

                            The Microsoft Threat Intelligence Podcast is produced by Microsoft, Hangar Studios and distributed as part of N2K media network. 

                            37 min
                          • From Identity Compromise to AI Defense: Inside Modern Incident Response

                            This week we are taking you back to Black Hat USA 2026 and exploring two sides of the security landscape. 

                            First, Microsoft incident response experts Adrian Hill and Terry Mee break down identity-based attacks, from compromised credentials and MFA bypasses to containment, logging, access controls, and the growing risks surrounding AI agents. 

                            Then, members of Microsoft’s Defender Purple Team discuss how they recreate full attack chains, including emerging AI-driven techniques, to identify detection gaps, strengthen defenses, and use AI to accelerate security research while keeping human expertise in the loop. 


                            In this episode you’ll learn: 

                            • Why identity is at the center of modern security incidents 

                              • How attackers can bypass MFA and maintain access through sessions, tokens, and other forms of persistence 

                                • Why logging and long-term data retention are critical during incident response 

                                  • How purple teams recreate full attack chains to uncover gaps in detection and response 

                                    • Where AI can accelerate security research, and where deterministic systems and human oversight still matter 

                                      • Why AI agents introduce new risks around access, permissions, and trust 

                                      • Some questions we ask: 

                                        • What should organizations be logging and retaining for incident response? 

                                          • Where do organizations underestimate SaaS, OAuth, and identity persistence risks? 

                                            • When should defenders contain an attacker versus continue gathering intelligence? 

                                              • How does attacking an AI-enabled system begin to look like traditional offensive security? 

                                                • Where should security researchers trust AI, and where should they rely on deterministic systems? 

                                                  • What should security teams understand about the exposure and permissions of their AI agents? 

                                                  •  

                                                     Resources:  

                                                    View Elliot Volkman on LinkedIn  

                                                     

                                                    Related Microsoft Podcasts:                   

                                                    • Afternoon Cyber Tea with Ann Johnson 

                                                      • The BlueHat Podcast 

                                                        • Uncovering Hidden Risks     

                                                        •  

                                                          Discover and follow other Microsoft podcasts at microsoft.com/podcasts  

                                                           

                                                          Get the latest threat intelligence insights and guidance at Microsoft Security Insider 

                                                           

                                                          The Microsoft Threat Intelligence Podcast is produced by Microsoft, Hangar Studios and distributed as part of N2K media network. 

                                                          51 min
                                                        • Why Threat Actors Love Your RMM

                                                          In this episode of the Microsoft Threat Intelligence Podcast, recorded live at Black Hat, Microsoft Threat Intelligence Director Elliot Volkman is joined by Andrew “Spike” Brandt, Principal Threat Intelligence Incident Commander at Huntress. 

                                                          They explore how cybercriminals are increasingly abusing legitimate remote monitoring and management (RMM) tools, why trusted remote-access software has become an attractive alternative to traditional malware, and how AI is improving phishing and social engineering. Spike also breaks down a real-world attack that deployed multiple RMM tools to maintain access, shares stories from his years of interacting directly with threat actors and offers practical guidance for detecting suspicious RMM activity before it leads to ransomware or data theft. 


                                                          In this episode you’ll learn:      

                                                          • How AI is making phishing lures and fake websites more convincing 

                                                            • Why trusted remote-access software can evade traditional endpoint detection 

                                                              • How security teams can identify and block unauthorized RMM activity 

                                                              • Some questions we ask:     

                                                                • What information are attackers looking for once they gain access? 

                                                                  • Why are attackers choosing legitimate tools instead of traditional malware? 

                                                                    • How does compromised access eventually lead to ransomware or data theft? 

                                                                    •  

                                                                      Resources:  

                                                                      Huntress report on RMM abuse 

                                                                      View Andrew Brandt on LinkedIn  

                                                                      View Elliot Volkman on LinkedIn  

                                                                       

                                                                      Related Microsoft Podcasts:                   

                                                                      • Afternoon Cyber Tea with Ann Johnson 

                                                                        • The BlueHat Podcast 

                                                                          • Uncovering Hidden Risks     

                                                                          •  

                                                                            Discover and follow other Microsoft podcasts at microsoft.com/podcasts  

                                                                             

                                                                            Get the latest threat intelligence insights and guidance at Microsoft Security Insider 

                                                                             

                                                                            The Microsoft Threat Intelligence Podcast is produced by Microsoft, Hangar Studios and distributed as part of N2K media network. 

                                                                            29 min
                                                                          • JADEPUFFER: An End-to-End Agentic-Led Ransomware Attack

                                                                            In this episode of the Microsoft Threat Intelligence Podcast, we are joined by Sysdig’s Michael Clark and Crystal Morin to discuss JADEPUFFER, one of the first documented cases of an LLM conducting an end-to-end ransomware operation. They break down how the agent, and the direction of a threat actor was identified, how AI is lowering the barrier to entry for ransomware, and why speed and adaptability are changing the threat landscape. Plus, they explore what organizations can do to defend against AI-powered attacks, from basic security hygiene and exposure management to better understanding their growing AI infrastructure. 

                                                                             

                                                                            In this episode you’ll learn:      

                                                                            • How Jade Puffer used an LLM to conduct a ransomware attack 

                                                                              • Why agentic AI can make cyberattacks faster and more adaptable 

                                                                                • How organizations can better protect their growing AI infrastructure 

                                                                                • Some questions we ask:     

                                                                                  • How did you determine an LLM was conducting the attack? 

                                                                                    • What basic security practices are most important against these attacks? 

                                                                                      • Does AI allow less-sophisticated threat actors to carry out more advanced attacks? 

                                                                                      •  

                                                                                        Resources:  

                                                                                        Read the research on JADEPUFFER 

                                                                                        View Crystal Morin on LinkedIn  

                                                                                        View Michael Clark on LinkedIn  

                                                                                        View Elliot Volkman on LinkedIn  

                                                                                         

                                                                                        Related Microsoft Podcasts:                   

                                                                                        • Afternoon Cyber Tea with Ann Johnson 

                                                                                          • The BlueHat Podcast 

                                                                                            • Uncovering Hidden Risks     


                                                                                            • Discover and follow other Microsoft podcasts at microsoft.com/podcasts  

                                                                                               

                                                                                              Get the latest threat intelligence insights and guidance at Microsoft Security Insider 

                                                                                               

                                                                                              The Microsoft Threat Intelligence Podcast is produced by Microsoft, Hangar Studios and distributed as part of N2K media network. 

                                                                                              32 min
                                                                                            • Shifts We Are Seeing Across Social Engineering, Post-Disruption Impact Report

                                                                                              In this episode of the Microsoft Threat Intelligence Podcast, Microsoft Threat Intelligence Director⁠ Elliot Volkman is joined by Microsoft Principal Threat Intelligence Analyst Crane Hassold to explore how phishing and social engineering attacks are changing beyond email. They discuss the rise of QR code phishing, Microsoft Teams scams, SMS-based attacks, and why attackers continue to follow wherever people communicate.

                                                                                              Crane also shares practical security recommendations for organizations and explains how Microsoft's disruption of the Tycoon2FA phishing-as-a-service platform led to a dramatic decline in malicious activity while reshaping the broader phishing landscape. 


                                                                                              In this episode you’ll learn:     

                                                                                              • How phishing attacks are evolving beyond email

                                                                                                • The security basics every organization should prioritize

                                                                                                • How attackers are exploiting Microsoft Teams and SMS

                                                                                                • Some questions we ask:    

                                                                                                  • What are you seeing in today's social engineering and phishing landscape?

                                                                                                  • How impactful was the Tycoon 2FA disruption?

                                                                                                  • Has Tycoon activity shifted elsewhere after the disruption?

                                                                                                  • Resources: 

                                                                                                    View Elliot Volkman on LinkedIn 

                                                                                                    View Crane Hassold on LinkedIn 


                                                                                                    Related Microsoft Podcasts:

                                                                                                    • Afternoon Cyber Tea with Ann Johnson

                                                                                                    • The BlueHat Podcast

                                                                                                    • Uncovering Hidden Risks    


                                                                                                    • Discover and follow other Microsoft podcasts at microsoft.com/podcasts 


                                                                                                      Get the latest threat intelligence insights and guidance at Microsoft Security Insider


                                                                                                      The Microsoft Threat Intelligence Podcast is produced by Microsoft, Hangar Studios and distributed as part of N2K media network.

                                                                                                      25 min
                                                                                                    • A Farewell from Sherrod: New Season Coming Soon

                                                                                                      As we close out season three of the podcast, Sherrod offers her farewell message as she takes on a new threat intelligence leadership role outside of Microsoft. Our executive producer also joins to briefly share our plans for season four, with new faces and voices joining future episodes.

                                                                                                      9 min
                                                                                                    • Behind the Book: Threat-Driven Software Development

                                                                                                      In this episode of the Microsoft Threat Intelligence Podcast, host⁠ ⁠⁠Sherrod DeGrippo is joined by co-authors Michael Howard, Lee Holmes, and Shawn Hernan for a discussion on their new book, Threat-Driven Software Development: Defending Online Services from Modern Threat Actors.  


                                                                                                      Together, they explore how security teams and software developers can build more resilient systems by understanding how real-world threat actors operate. From threat modeling and operational security to the evolving role of AI in both cyber defense and cybercrime, the conversation examines lessons learned from major security incidents and why secure design must be a priority from the earliest stages of software development. 


                                                                                                      In this episode you’ll learn:      

                                                                                                      • Why security should be driven by real-world threat actor behavior 

                                                                                                        • How developers can reduce risk through better design and operational practices 

                                                                                                          • The role of threat modeling in modern software development 

                                                                                                          • Some questions we ask:     

                                                                                                            • How did the idea for Threat-Driven Software Development come about? 

                                                                                                              • Why is operational security just as important as application security? 

                                                                                                                • What do you hope readers take away from this book? 

                                                                                                                • Resources:  

                                                                                                                  View Lee Holmes on LinkedIn  

                                                                                                                  View Michael Howard on LinkedIn  

                                                                                                                  View Shawn Hernan on LinkedIn  

                                                                                                                  View Sherrod DeGrippo on LinkedIn  

                                                                                                                   

                                                                                                                  Related Microsoft Podcasts:                   

                                                                                                                  • The BlueHat Podcast 

                                                                                                                    • Uncovering Hidden Risks     


                                                                                                                    • Discover and follow other Microsoft podcasts at microsoft.com/podcasts  

                                                                                                                       

                                                                                                                      Get the latest threat intelligence insights and guidance at Microsoft Security Insider 

                                                                                                                       

                                                                                                                      The Microsoft Threat Intelligence Podcast is produced by Microsoft, Hangar Studios and distributed as part of N2K media network. 

                                                                                                                      1 hr
                                                                                                                    • Casey Ellis on How AI Is Reshaping Vulnerability Research and Patching

                                                                                                                      In this episode of the Microsoft Threat Intelligence Podcast, host⁠ ⁠⁠Sherrod DeGrippo sits down with Casey Ellis, founder of Bugcrowd and co-founder of disclose.io, to explore how AI is reshaping vulnerability research, bug bounty programs, and the future of cyber defense. They discuss the growing volume of vulnerabilities, the challenges of responsible disclosure, the rise of AI-assisted hacking, and what happens when increasingly powerful tools are placed in the hands of both defenders and attackers. The conversation also dives into the human side of cybersecurity, from community and creativity to maintaining optimism and connection in an AI-driven world. 


                                                                                                                      In this episode you’ll learn:      

                                                                                                                      • How AI is changing vulnerability research for both defenders and threat actors 

                                                                                                                        • The challenges of responsible disclosure in an age of rapid software development 

                                                                                                                          • Why cybersecurity experts believe vulnerability volume is growing faster than ever 

                                                                                                                            Some questions we ask:      

                                                                                                                            • How will AI affect individual threat actors, hacktivists, and cybercriminals? 

                                                                                                                              • What tasks should humans continue doing instead of outsourcing AI? 

                                                                                                                                • When does publishing vulnerability research help defenders versus help threat actors? 

                                                                                                                                  Resources:  

                                                                                                                                  View Casey Ellis on LinkedIn  

                                                                                                                                  View Sherrod DeGrippo on LinkedIn  

                                                                                                                                   

                                                                                                                                  Related Microsoft Podcasts:                   

                                                                                                                                  • The BlueHat Podcast 

                                                                                                                                    • Uncovering Hidden Risks     


                                                                                                                                      Discover and follow other Microsoft podcasts at microsoft.com/podcasts  


                                                                                                                                      Get the latest threat intelligence insights and guidance at Microsoft Security Insider 

                                                                                                                                       

                                                                                                                                      The Microsoft Threat Intelligence Podcast is produced by Microsoft, Hangar Studios and distributed as part of N2K media network. 

                                                                                                                                      1 hr 4 min
                                                                                                                                    • Hot Cybercrime Summer:  Smishing, Supply Chains, and Sleuthcon

                                                                                                                                      In this episode of the Microsoft Threat Intelligence Podcast, host⁠ ⁠⁠Sherrod DeGrippo sits down with Aurora Johnson of SpyCloud and Amitai Cohen of Wiz ahead of SleuthCon to explore two rapidly changing corners of the cybercrime landscape.  

                                                                                                                                      Aurora breaks down the highly organized Chinese-language smishing ecosystem, revealing how phishing operations, fraud networks, and cash-out schemes work together like a mature business.  

                                                                                                                                      Amitai examines the growing threat to software supply chains, explaining how groups like Team PCP are exploiting CI/CD pipelines, open-source dependencies, and AI-assisted malware development.  

                                                                                                                                      Together, they discuss the industrialization of cybercrime, the role of automation and AI, and why defenders must rethink how they secure today's interconnected digital ecosystem.  


                                                                                                                                      In this episode you’ll learn:      

                                                                                                                                      • Why cybercrime ecosystems now operate like sophisticated businesses 

                                                                                                                                        • How NFC relay attacks are being used to cash out stolen credit card data 

                                                                                                                                          • The role Telegram marketplaces play in modern fraud operations 

                                                                                                                                            Some questions we ask:     

                                                                                                                                            • How industrialized has modern cybercrime become? 

                                                                                                                                              • What clues suggest threat actors are using AI to create malware? 

                                                                                                                                                • What are defenders missing about CI/CD pipelines as an attack surface? 

                                                                                                                                                  Resources:  

                                                                                                                                                  View Aurora Johnson on LinkedIn  

                                                                                                                                                  View Amitai Cohen on LinkedIn  

                                                                                                                                                  View Sherrod DeGrippo on LinkedIn  

                                                                                                                                                   

                                                                                                                                                  Related Microsoft Podcasts:                   

                                                                                                                                                  • The BlueHat Podcast 

                                                                                                                                                    • Uncovering Hidden Risks     


                                                                                                                                                      Discover and follow other Microsoft podcasts at microsoft.com/podcasts  

                                                                                                                                                       

                                                                                                                                                      Get the latest threat intelligence insights and guidance at Microsoft Security Insider 

                                                                                                                                                       

                                                                                                                                                      The Microsoft Threat Intelligence Podcast is produced by Microsoft, Hangar Studios and distributed as part of N2K media network. 

                                                                                                                                                      41 min
                                                                                                                                                    • Supply Chain Attacks: Open Source or Open Door?

                                                                                                                                                      In this episode of the Microsoft Threat Intelligence Podcast, host⁠ ⁠⁠Sherrod DeGrippo is joined by Allie Luhrs and Mario Samolis from Microsoft Security to explore the growing threat of open source software supply chain attacks. They discuss how malicious NPM packages, compromised developer ecosystems, AI-generated attacks, and software dependency risks are reshaping modern incident response, while sharing insights from their recent presentation at BlueHat IL 2025.  


                                                                                                                                                      In this episode you’ll learn:      

                                                                                                                                                      • How attackers are targeting open source software ecosystems at scale 

                                                                                                                                                        • Why AI is accelerating both cyberattacks and threat detection 

                                                                                                                                                          • What was uncovered during their BlueHat presentation on modern software supply chain attacks 

                                                                                                                                                            Some questions we ask:     

                                                                                                                                                            • What patterns did you uncover in NPM attack campaigns? 

                                                                                                                                                              • Should developers rely on dependencies or build everything themselves? 

                                                                                                                                                                • Why should organizations pay closer attention to open source security risks? 

                                                                                                                                                                  Resources:  

                                                                                                                                                                  View Allie Luhrs on LinkedIn  

                                                                                                                                                                  View Mario Samolis on LinkedIn  

                                                                                                                                                                  View Sherrod DeGrippo on LinkedIn  

                                                                                                                                                                   

                                                                                                                                                                  Related Microsoft Podcasts:                   

                                                                                                                                                                  • Afternoon Cyber Tea with Ann Johnson 

                                                                                                                                                                    • The BlueHat Podcast 

                                                                                                                                                                      • Uncovering Hidden Risks     

                                                                                                                                                                         

                                                                                                                                                                        Discover and follow other Microsoft podcasts at microsoft.com/podcasts  

                                                                                                                                                                         

                                                                                                                                                                        Get the latest threat intelligence insights and guidance at Microsoft Security Insider 

                                                                                                                                                                         

                                                                                                                                                                        The Microsoft Threat Intelligence Podcast is produced by Microsoft, Hangar Studios and distributed as part of N2K media network. 

                                                                                                                                                                        39 min

                                                                                                                                                                      About Microsoft Threat Intelligence Podcast

                                                                                                                                                                      From the publisher's feed

                                                                                                                                                                      Join us to hear stories from the Microsoft Threat Intelligence community as they navigate the ever-evolving threat landscape - uncovering APTs, cybercrime gangs, malware, vulnerabilities, and other…

                                                                                                                                                                      More shows like Microsoft Threat Intelligence Podcast

                                                                                                                                                                      Hacked by Hacked

                                                                                                                                                                      Hacked

                                                                                                                                                                      192 Listeners

                                                                                                                                                                      Security Now (Audio) by TWiT

                                                                                                                                                                      Security Now (Audio)

                                                                                                                                                                      2,010 Listeners

                                                                                                                                                                      The Talk Show With John Gruber by Daring Fireball / John Gruber

                                                                                                                                                                      The Talk Show With John Gruber

                                                                                                                                                                      3,143 Listeners

                                                                                                                                                                      Risky Business by Risky Business Media

                                                                                                                                                                      Risky Business

                                                                                                                                                                      375 Listeners

                                                                                                                                                                      SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast) by Johannes B. Ullrich

                                                                                                                                                                      SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

                                                                                                                                                                      652 Listeners

                                                                                                                                                                      CyberWire Daily by N2K Networks

                                                                                                                                                                      CyberWire Daily

                                                                                                                                                                      1,028 Listeners

                                                                                                                                                                      Smashing Security by Graham Cluley

                                                                                                                                                                      Smashing Security

                                                                                                                                                                      317 Listeners

                                                                                                                                                                      Click Here by Recorded Future News

                                                                                                                                                                      Click Here

                                                                                                                                                                      420 Listeners

                                                                                                                                                                      Darknet Diaries by Jack Rhysider

                                                                                                                                                                      Darknet Diaries

                                                                                                                                                                      8,058 Listeners

                                                                                                                                                                      Cybersecurity Today by David Shipley

                                                                                                                                                                      Cybersecurity Today

                                                                                                                                                                      179 Listeners

                                                                                                                                                                      Hacking Humans by N2K Networks

                                                                                                                                                                      Hacking Humans

                                                                                                                                                                      314 Listeners

                                                                                                                                                                      CISO Series Podcast by David Spark, Mike Johnson, and Andy Ellis

                                                                                                                                                                      CISO Series Podcast

                                                                                                                                                                      191 Listeners

                                                                                                                                                                      Cybersecurity Headlines by CISO Series

                                                                                                                                                                      Cybersecurity Headlines

                                                                                                                                                                      138 Listeners

                                                                                                                                                                      Cyber Hack by BBC World Service

                                                                                                                                                                      Cyber Hack

                                                                                                                                                                      1,596 Listeners

                                                                                                                                                                      Risky Bulletin by Risky Business Media

                                                                                                                                                                      Risky Bulletin

                                                                                                                                                                      46 Listeners