Microsoft Threat Intelligence Podcast

Open SesameOp: Abusing trusted AI platforms to host a C2 server


Listen Later

To kick off Season 3 of Microsoft Threat Intelligence Podcast, host⁠ ⁠⁠Sherrod DeGrippo is joined by Microsoft security researchers Anna Seitz and Jonathan Checchi.  

Our guests examine two developments shaping today’s threat landscape: the cloud-native evolution of ransomware group Storm-0501 and the SesameOp backdoor’s abuse of trusted AI platforms for stealthy command-and-control. The discussion highlights how identity, hybrid-cloud pivot points, and federated authentication enable high-impact attacks without traditional malware, and why policy-compliant platform abuse is becoming harder to detect.  

Sherrod, Anna, and Jonathan provide guidance for defenders around enforcing MFA, tightening conditional access and identity controls, monitoring across cloud and on-prem environments, and partnering with platform providers to disrupt emerging attacker tradecraft. 


In this episode you’ll learn:      

  • What happens when threat actors gain control of highly privileged identities 

    • Why monitoring identity behavior is as critical as monitoring endpoints 

      • How attacker tactics are adapting to environments that blend cloud and on-prem systems 

         Some questions we ask:     

        • What does recent threat activity tell us about where the landscape is headed? 

          • How is Storm-0501 using federated authentication in their operations? 

            • What should security teams focus on as AI becomes more integrated into systems? 

              Resources:  

              • View Anna Seitz on LinkedIn  

                • View Sherrod DeGrippo on LinkedIn  

                   Related Microsoft Podcasts:                   

                  • Afternoon Cyber Tea with Ann Johnson 

                    • The BlueHat Podcast 

                      • Uncovering Hidden Risks     

                         

                        Discover and follow other Microsoft podcasts at microsoft.com/podcasts  

                         

                        Get the latest threat intelligence insights and guidance at Microsoft Security Insider 

                         

                        The Microsoft Threat Intelligence Podcast is produced by Microsoft, Hangar Studios and distributed as part of N2K media network. 

                        ...more
                        View all episodesView all episodes
                        Download on the App Store

                        Microsoft Threat Intelligence PodcastBy Microsoft

                        • 5
                        • 5
                        • 5
                        • 5
                        • 5

                        5

                        22 ratings


                        More shows like Microsoft Threat Intelligence Podcast

                        View all
                        Hacked by Hacked

                        Hacked

                        189 Listeners

                        Security Now (Audio) by TWiT

                        Security Now (Audio)

                        2,005 Listeners

                        The Talk Show With John Gruber by Daring Fireball / John Gruber

                        The Talk Show With John Gruber

                        3,144 Listeners

                        Risky Business by Patrick Gray

                        Risky Business

                        374 Listeners

                        SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast) by Johannes B. Ullrich

                        SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

                        648 Listeners

                        CyberWire Daily by N2K Networks

                        CyberWire Daily

                        1,034 Listeners

                        Smashing Security by Graham Cluley

                        Smashing Security

                        322 Listeners

                        Click Here by Recorded Future News

                        Click Here

                        422 Listeners

                        Darknet Diaries by Jack Rhysider

                        Darknet Diaries

                        8,113 Listeners

                        Cybersecurity Today by Jim Love

                        Cybersecurity Today

                        178 Listeners

                        Hacking Humans by N2K Networks

                        Hacking Humans

                        316 Listeners

                        CISO Series Podcast by David Spark, Mike Johnson, and Andy Ellis

                        CISO Series Podcast

                        191 Listeners

                        Cybersecurity Headlines by CISO Series

                        Cybersecurity Headlines

                        138 Listeners

                        Cyber Hack by BBC World Service

                        Cyber Hack

                        1,601 Listeners

                        Risky Bulletin by risky.biz

                        Risky Bulletin

                        44 Listeners