ShadowTalk: Powered by ReliaQuest

ShadowTalk: Powered by ReliaQuest

Download on the App Store

ShadowTalk: Powered by ReliaQuest episodes

  • DPRK Insider Threats: How Remote-Worker Tactics Are Evolving

    Security leaders should be asking a hard question: if a remote hire looks legitimate at every checkpoint, what would expose the operation? Security operations is the defense layer of the business, and the teams defending it need AI to move faster across the full environment.

    In this episode of ShadowTalk, Daxton Wirth and John Dilgen share practical guidance on what to verify, where teams miss inconsistencies, and how HR, onboarding, identity, and security can investigate together before access turns into exposure.

    Resources: https://linktr.ee/ReliaQuestShadowTalk

    John Dilgen: Cyber Threat Intelligence Analyst at ReliaQuest, where he specializes in researching cyber threats impacting ReliaQuest customers. With a strong technical background, he previously served as an Incident Response Analyst and Trainer at ReliaQuest.

    Daxton Wirth: Threat Hunter at ReliaQuest specialized in DPRK research and identification for the last two years. Daxton also specializes in breach response including investigating and remediating complex intrusions. 

    31 min
  • CISO Wisdom: Turning Security Investments Into Measurable Risk Reduction

    Security teams are contending with more tools, alerts, and vulnerabilities than ever—but volume does not necessarily equal security. Jigar Shah joins us to discuss how organizations can automate repetitive work, prioritize vulnerabilities based on business risk, build identity-driven security strategies, and connect cybersecurity investments to measurable outcomes. With two decades of leadership experience across healthcare, financial services, retail, and consulting, Jigar brings a business-focused perspective on helping security leaders communicate risk and resilience to the board and C-suite.

     A Question Your Organization Should Be Asking Right Now:

    • How quickly can your organization make risk-based decisions?

    Resources: https://linktr.ee/ReliaQuestShadowTalk

    Jigar Shah: Transformational IT, data, and cybersecurity executive with two decades of leadership experience across healthcare, financial services, retail, and consulting. He brings a distinctive blend of technology, business, and legal expertise to overseeing complex enterprise initiatives, including cybersecurity programs, cloud migrations, M&A integrations, and risk management for large regulated organizations. A passionate advocate for automation, identity-driven security, and business-aligned cyber strategy, Jigar excels at translating technical priorities into measurable outcomes for boards and C-suite leaders.

    John Dilgen: Cyber Threat Intelligence Analyst at ReliaQuest, where he specializes in researching cyber threats impacting ReliaQuest customers. With a strong technical background, he previously served as an Incident Response Analyst and Trainer at ReliaQuest.

    34 min
  • Fake NDAs, Real Money: Inside the M&A Social Engineering Playbook

    In this episode, we examine the Phantom Deal campaign, in which threat actors used publicly available details about companies’ acquisition histories, subsidiaries, executives, and employees to create convincing fake M&A scenarios. The goal: persuade employees to initiate large financial transfers while keeping conversations off corporate communication channels.

    We also cover a recent series of zero-day disclosures affecting major endpoint-security and Windows products. These vulnerabilities reinforce a critical operational reality: organizations must be prepared to detect and respond even when endpoint-security visibility is weakened or unavailable.

    Two questions your organization should be asking right now:

    • If an employee received an urgent, confidential payment request from an apparent executive, could they independently verify the request without using the communication channel chosen by the attacker?
    • If an endpoint-security tool went blind during an attack, what identity, network, cloud, and Windows telemetry could your team use to detect and contain the activity?

    Resources: https://linktr.ee/ReliaQuestShadowTalk

    John Dilgen: Cyber Threat Intelligence Analyst at ReliaQuest, where he specializes in researching cyber threats impacting ReliaQuest customers. With a strong technical background, he previously served as an Incident Response Analyst and Trainer at ReliaQuest.

    Brandon Tirado: Director of GreyMatter Operations for ReliaQuest. A skilled cyber defense professional with a unique combination of management and hands-on experience. With a deep understanding of adversary motives and the tactics, techniques, and procedures (TTPs) they use to achieve their goals, Brandon enjoys operationalizing his knowledge to make it more difficult for adversaries to operate within the environments of ReliaQuest customers. His managerial and hands-on experience enriches ShadowTalk with practical and strategic viewpoints.

    29 min
  • From Vulnerability Research to Domain Admin in Minutes

    AI is changing the economics of cyberattacks. In this episode, we examine how a suspected threat actor used AI agents to accelerate PaperCut vulnerability research, exploit development, target identification, and post-compromise activity—moving from initial access to domain administrator access in as little as seven minutes.

    We also explore recent reporting on large-scale AI-model distillation campaigns by China-based companies and what the increasing availability of frontier-level AI capabilities could mean for future nation-state and criminal threat operations.

    Two questions your organization should be asking right now:

    • If an attacker gained initial access through an internet-facing system tomorrow, could your team detect and contain the activity in less than seven minutes?
    • Are you evaluating vulnerabilities, exposed services, and identity privileges as connected attack paths—or as separate security issues?

    Resources: https://linktr.ee/ReliaQuestShadowTalk

    John Dilgen: Cyber Threat Intelligence Analyst at ReliaQuest, where he specializes in researching cyber threats impacting ReliaQuest customers. With a strong technical background, he previously served as an Incident Response Analyst and Trainer at ReliaQuest.

    Alexandra Moore: Manager of Threat Intelligence at ReliaQuest, where she leads intelligence analysis and customer dissemination to help organizations understand and respond to emerging cyber threats. Prior to this, she established and scaled monitoring across Russian-language cybercriminal platforms at Digital Shadows, building collection and analytical coverage to support digital risk protection capabilities.

    32 min
  • One Empty Field: The Email Security Bypass Letting Attackers Impersonate Your Executives

    Organizations rely on Microsoft 365's RejectDirectSend control to block internal email spoofing—but a structural gap lets attackers walk right past it. With nothing more than a basic Python script and an empty envelope sender, threat actors are impersonating executives, IT support, and finance teams to launch Business Email Compromise, payment fraud, and follow-on account takeover.

    Join hosts Alexandra Moore and John Dilgen as they discuss:

    • How an empty email header field bypasses RejectDirectSend and lands phishing in executive inboxes
    • How help desk impersonation combined with spoofed internal email creates a dangerous new pretext
    • Which controls—IP-restricted connectors, automated containment, and out-of-band verification—actually close the gap

     Two questions your organization should be asking right now:

    • If someone attempted a Direct Send from an unauthorized IP into your tenant tomorrow, would it be rejected?
    • When was the last time you tested whether your employees follow out-of-band verification procedures under pressure?

    Resources: https://linktr.ee/ReliaQuestShadowTalk

    John Dilgen: Cyber Threat Intelligence Analyst at ReliaQuest, where he specializes in researching cyber threats impacting ReliaQuest customers. With a strong technical background, he previously served as an Incident Response Analyst and Trainer at ReliaQuest.

    Alexandra Moore: Manager of Threat Intelligence at ReliaQuest, where she leads intelligence analysis and customer dissemination to help organizations understand and respond to emerging cyber threats. Prior to this, she established and scaled monitoring across Russian-language cybercriminal platforms at Digital Shadows, building collection and analytical coverage to support digital risk protection capabilities.

    30 min
  • From Data Dumps to Critical Findings: The New Era of Data Extortion

    Threat actors do not see old email archives, forgotten shared drives, and outdated CRM exports as clutter. They see them as searchable inventory. With AI-assisted analysis, attackers can rapidly identify sensitive communications, regulatory exposure, customer relationships, and credentials buried in stolen data.

    Join hosts John Dilgen and Brandon Tirado as they discuss:

    • Why data theft has become a central component of modern extortion operations
    • How AI and automation are helping attackers analyze hundreds of thousands of files at machine speed
    • Why “soft data,” including invoices and project documents, can fuel downstream fraud and social engineering
    • How strong retention, credential-rotation, and OAuth-management practices reduce breach impact

    Two questions your organization should be asking right now:

    • How much data does your organization retain beyond its business or regulatory need?
    • Could your team rotate hundreds of exposed credentials—not just one—before an attacker uses them?

    John Dilgen: Cyber Threat Intelligence Analyst at ReliaQuest, where he specializes in researching cyber threats impacting ReliaQuest customers. With a strong technical background, he previously served as an Incident Response Analyst and Trainer at ReliaQuest.


    Brandon Tirado: Director of GreyMatter Operations for ReliaQuest. A skilled cyber defense professional with a unique combination of management and hands-on experience. With a deep understanding of adversary motives and the tactics, techniques, and procedures (TTPs) they use to achieve their goals, Brandon enjoys operationalizing his knowledge to make it more difficult for adversaries to operate within the environments of ReliaQuest customers. His managerial and hands-on experience enriches ShadowTalk with practical and strategic viewpoints.

    29 min
  • Vishing at Scale: Inside the Criminal SaaS Platform Enabling Account Takeover

    What if a threat actor already knew your name, your job title, your manager's name, and your direct number before they ever picked up the phone? That's not a hypothetical — that's Work Panel. A new report gave us a rare inside look at the criminal SaaS platform enabling vishing campaigns at scale, and the findings are a wake-up call.

     

    Join hosts John Dilgen and Alexandra Moore as they break down:

    ✅ How Work Panel packages phishing infrastructure, team management, and real-time credential capture into a single automated console

    ✅ Why threat actors are now impersonating HR to make their calls more convincing

    ✅ How legitimate B2B platforms are being weaponized to personalize attacks before a single call is made

    ✅ The specific controls that can stop these campaigns before they reach your users

     

    🔑 Two questions your organization should be asking right now:

    • If a caller already knew your employee's job title, manager's name, and direct number — would your team recognize it as a social engineering attempt, or fall for it?
    • Is your organization still relying on push-based MFA as its primary account takeover defense?

     

    👉 Tune in for expert insights and practical takeaways: ShadowTalk – ReliaQuest

    👉 Find more podcast platforms, resources, and our listener feedback survey: ShadowTalk Official: X | Linktree

    32 min
  • Nation-State Actors: Iran’s PLC Attacks, Russia’s Zero-Click Email Exploit, and North Korea’s Fake Employees

    Three nation-states. Three distinct playbooks. Iranian actors are targeting internet-exposed industrial controllers and disabling critical safety systems. A Russian threat group built a zero-click email exploit that steals 90 days of inbox data the moment a user views a message. And North Korean operatives are applying for software-development jobs at Western companies—and getting hired.

    Join hosts John Dilgen and Tehman Tariq as they break down:

    ✅ How Iranian actors manipulate PLC safety logic while keeping operators in the dark

    ✅ Why Russia’s zero-click exploit creates a major email-security and data-exfiltration risk

    ✅ How North Korean operatives use forged and stolen identities to infiltrate organizations as employees

    🔑 Two questions your organization should be asking right now:

    • Could your security team identify and secure internet-exposed PLCs, HMIs, and SCADA systems before an adversary does?
    • Does your hiring process include controls to detect AI-generated documents, stolen identities, and malicious job applicants?

    👉 Tune in for expert insights and practical takeaways: ShadowTalk – ReliaQuest

    👉 Find more podcast platforms, resources, and our listener feedback survey: ShadowTalk Official: X | Linktree

    28 min
  • When AI Escapes the Lab: The Hugging Face Breach, PyPI Malware, and What It Means for Defenders

    Fully autonomous attacks are here. AI agents escape a test environment, exploit zero-days, coordinate through shared infrastructure, and breach a production company—generating more than 17,000 security events along the way. Elsewhere, another model autonomously publishes malware to PyPI, while AI agents target real open-source developers with tailored social engineering.

     Join hosts John Dilgen and Tehman Tariq as they break down:

    ✅ How AI agents escaped containment and compromised Hugging Face infrastructure

    ✅ Why Claude’s autonomous PyPI attack signals growing software-supply-chain risk

    ✅ How coordinated AI agents deceived real developers

    🔑 Two questions your organization should be asking right now:

    • Could your SOC investigate and contain 17,000 coordinated events at machine speed?
    • What deception controls do you have in place to slow an AI agent attack? 

    👉 Tune in for expert insights and practical takeaways: ShadowTalk – ReliaQuest

    👉 Find more podcast platforms, resources, and our listener feedback survey: ShadowTalk Official: X | Linktree

    24 min
  • The Gentlemen, Deadlock, and Clop: The Groups Driving Ransomware & Extortion in 2026

    An affiliate receives a ready-made intrusion kit — pre-compromised targets, an EDR killer, and a full deployment workflow included. No building from scratch. No long ramp-up. Just deploy, observe, and iterate. That's the future of ransomware; it's how the new number-one group operated in Q2 2026. And it's just one of three stories reshaping the extortion landscape right now.

    Join hosts Brandon Tirado and John Dilgen as they break down:

    • How The Gentlemen's pre-packaged affiliate kit drove 580% leak-site growth
    • Why Deadlock's Polygon blockchain C2 defeats network defenses
    • Clop's latest campaign targeting an industrial enterprise application

     Two questions your organization should be asking right now:

    • Do you know exactly where your EDR coverage ends?
    • If a critical vendor were compromised tonight, would you hear it from them first — or from your own monitoring?

    John Dilgen: Cyber Threat Intelligence Analyst at ReliaQuest, where he specializes in researching cyber threats impacting ReliaQuest customers. With a strong technical background, he previously served as an Incident Response Analyst and Trainer at ReliaQuest.

    Brandon Tirado: Director of GreyMatter Operations for ReliaQuest. A skilled cyber defense professional with a unique combination of management and hands-on experience. With a deep understanding of adversary motives and the tactics, techniques, and procedures (TTPs) they use to achieve their goals, Brandon enjoys operationalizing his knowledge to make it more difficult for adversaries to operate within the environments of ReliaQuest customers. His managerial and hands-on experience enriches ShadowTalk with practical and strategic viewpoints.

    37 min

About ShadowTalk: Powered by ReliaQuest

From the publisher's feed

Want to hear what industry experts really think about the cyber threats they face? ShadowTalk is a weekly cybersecurity podcast, made by practitioners for practitioners, featuring analytical…

More shows like ShadowTalk: Powered by ReliaQuest

Hacked by Hacked

Hacked

193 Listeners

Security Now (Audio) by TWiT

Security Now (Audio)

2,011 Listeners

WSJ Tech News Briefing by The Wall Street Journal

WSJ Tech News Briefing

1,644 Listeners

Risky Business by Risky Business Media

Risky Business

374 Listeners

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast) by Johannes B. Ullrich

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

650 Listeners

CyberWire Daily by N2K Networks

CyberWire Daily

1,027 Listeners

Click Here by Recorded Future News

Click Here

418 Listeners

Darknet Diaries by Jack Rhysider

Darknet Diaries

8,061 Listeners

Cybersecurity Today by David Shipley

Cybersecurity Today

179 Listeners

CISO Series Podcast by David Spark, Mike Johnson, and Andy Ellis

CISO Series Podcast

191 Listeners

True Spies: Espionage | Investigation | Crime | Murder | Detective | Politics by SPYSCAPE

True Spies: Espionage | Investigation | Crime | Murder | Detective | Politics

1,943 Listeners

Cybersecurity Headlines by CISO Series

Cybersecurity Headlines

137 Listeners

Cyber Hack by BBC World Service

Cyber Hack

1,594 Listeners

Risky Bulletin by Risky Business Media

Risky Bulletin

46 Listeners

The Economics Show by Financial Times

The Economics Show

139 Listeners