ShadowTalk: Powered by ReliaQuest

ShadowTalk: Powered by ReliaQuest

Download on the App Store

ShadowTalk: Powered by ReliaQuest episodes

  • Weekly: TeamCity and Supply Chain Risk, BEC Detections, Midnight Blizzard

    In this episode of ShadowTalk, host Chris, along with Corey and Caroline, discuss the latest news in cyber security and threat research. Topics this week include:

    • TeamCity Server critical vulnerability leaves potential for supply chain risk
    • ReliaQuest research into advanced business email compromise (BEC) detections
    • Microsoft compromised by Midnight Blizzard password spraying attack

    Resources: 

    • https://www.rapid7.com/blog/post/2024/03/04/etr-cve-2024-27198-and-cve-2024-27199-jetbrains-teamcity-multiple-authentication-bypass-vulnerabilities-fixed/ 
    • https://blog.jetbrains.com/teamcity/2024/03/our-approach-addressing-recently-discovered-vulnerabilities-in-teamcity-on-premises/ 
    • https://blog.jetbrains.com/teamcity/2024/03/preventing-exploits-jetbrains-ethical-approach-to-vulnerability-disclosure/ 
    • https://www.reliaquest.com/blog/business-email-compromise-detection/
    39 min
  • Weekly: ConnectWise Critical Vulnerabilities , Credential Theft, NIST Frameworks

    In this episode of ShadowTalk, host Chris, along with Fearghal and Kim, discuss the latest news in cyber security and threat research. Topics include:

    • An overview of the critical severity vulnerabilities affecting ConnectWise, patch now!
    • ReliaQuest research into Browser Credential Dumping attacks
    • The latest in the world of ransomware
    • Update to National Institute of Standards and Technology (NIST) framework

    Resources:

    • https://www.reliaquest.com/blog/browser-credential-dumping/ 
    23 min
  • Weekly: Lockbit Return, SAT Exercises, Optum Breach

    In this episode of ShadowTalk, host Chris, along with Ivan, Caroline, and one of ReliaQuest's CISOs Rick, discuss the latest news in cyber security and threat research. This week's topics include:

    • Lockbit return following law enforcement operation
    • Recent Structured Analytical Technique (SAT) exercises ran by ReliaQuest
    • The Optum Breach and what you need to know
    • 'SubdoMailing' malvertising campaign leveraging compromised domains

    Resources:

    • https://www.reliaquest.com/blog/lockbit-taken-down-what-comes-next/
    • https://www.reliaquest.com/blog/scattered-spider-attack-analysis-account-compromise/
    35 min
  • Weekly: Lockbit Taken Down, RMM Tool Abuse, Chinese Gov't Documents Exposed

    In this episode of ShadowTalk, host Chris, along with Brian, Kim, and one of ReliaQuest's CISOs Rick, discuss the latest news in cyber security and threat research. Topics this week include:

    • Lockbit taken down by NCA led operation. Does this spell the end for the ransomware group?
    • ReliaQuest research into abuse of Remote monitoring and management (RMM) tools
    • Insider leaks Chinese government documents on Github

    Resources:

    • https://www.reliaquest.com/blog/lockbit-taken-down-what-comes-next/
    39 min
  • Weekly: SocGholish, Volt Typhoon, ToothBrush DDoS' and Flipper Zero

    In this episode of ShadowTalk, host Chris, along with Marken and Corey, discuss the latest news in cyber security and threat research. Topics this week include:

    • ReliaQuest research into changes observed on SocGholish infection chain
    • Update to Volt Typhoon campaign affecting US CNI
    • Furore over reporting on Toothbrush smart devices reportedly used in DDoS attacks
    • Canada bans Flipper Zero consumer hacking device, over car theft concerns

     Resources:

    • https://www.reliaquest.com/blog/new-python-socgholish-infection-chain/
    • https://www.reliaquest.com/blog/socgholish-fakeupdates/
    46 min
  • Weekly: AnyDesk Breach, Deepfake Social Engineering, Q1 2024 Priorities

    In this episode of ShadowTalk, host Chris Morgan is joined by ReliaQuest CISO Rick Holland, Director of Threat Research Brandon Tirado and Intelligence Collection Analyst Fearghal Hughes to discuss the latest news in cyber security and threat research. Topics this week include:

    • Breach of Remote Desktop Application 'AnyDesk' results
    • Continued Ivanti vulnerability exploitations
    • The rise of BEC deepfake social engineering attacks
    • ReliaQuest's top priorities for the remainder of Q1 2024

    Resources:

    • https://event.on24.com/eventRegistration/EventLobbyServlet?target=reg20.jsp&eventid=4448957&sessionid=1&key=3FBF0E608FF3216DD9F1526D92EE5CCE&groupId=5180806&partnerref=website&sourcepage=register
    • https://event.on24.com/wcc/r/4387339/A63BC17298406ECD68AABFFEF416702B?partnerref=organic
    48 min
  • Weekly: Killnet 2.0, Baselining Detection Rules, Ransomware in Q4 2023

    In this episode of ShadowTalk, host Chris, along with James and Ivan, discuss the latest news in cyber security and threat research. Topics this week include:

    • The emergence of Killnet 2.0 
    • Best practices for Baselining Detection Rules
    • Insights from ReliaQuest's Q4 2023 Ransomware blog

    Resources:

    • https://www.reliaquest.com/blog/q4-2023-ransomware/
    30 min
  • Weekly: Midnight Blizzard Targets Microsoft, Recent Attacker Techniques, Citrix NetScaler Vulnerabilities

    In this episode of ShadowTalk, host Corey, along with Kim and Caroline, discuss the latest news in cyber security and threat research. Topics this week include:

    •  Midnight Blizzard Targeting Microsoft
    •  Threat research on Attacker techniques observed from Customer incidents
    •  Two new Citrix NetScaler vulnerabilities being exploited in the wild

    Resources:

    • https://www.reliaquest.com/blog/top-cyber-threat-techniques-q4-2023
    • https://msrc.microsoft.com/blog/2024/01/microsoft-actions-following-attack-by-nation-state-actor-midnight-blizzard/ 
    • https://www.theregister.com/2024/01/18/citrix_netscaler_bugs_attacked/
    32 min
  • Weekly: Ivanti Zero-days, Valid Account Misuse, Emerging risk from (IoT) devices

    In this episode of ShadowTalk, host Chris, along with Brian, Gjergji and ReliaQuest CISO Rick Holland, discuss the latest news in cyber security and threat research. Topics this week include:

    • Ivanti Zero-day vulnerabilities under mass exploitation
    • ReliaQuest research into misuse of Valid Accounts 
    • Risk posed through emerging Internet of Things (IoT) devices

    Resources:

    • https://forums.ivanti.com/s/article/CVE-2023-46805-Authentication-Bypass-CVE-2024-21887-Command-Injection-for-Ivanti-Connect-Secure-and-Ivanti-Policy-Secure-Gateways?language=en_US 
    41 min
  • Weekly: Cyber Threats Developments of 2023, Lockbit Targets Healthcare

    In this episode of ShadowTalk, host Chris, along with Marken and Fearghal, discuss the latest news in cyber security and threat research.  Topics this week include:

    • A recap of major developments in 2023: Ransomware, Business Email Compromise, Living off the land (LotL)
    • The influence of Generative AI on cyber threats
    • Lockbit targeting healthcare providers in Germany
    34 min

About ShadowTalk: Powered by ReliaQuest

From the publisher's feed

Want to hear what industry experts really think about the cyber threats they face? ShadowTalk is a weekly cybersecurity podcast, made by practitioners for practitioners, featuring analytical…

More shows like ShadowTalk: Powered by ReliaQuest

Hacked by Hacked

Hacked

193 Listeners

Security Now (Audio) by TWiT

Security Now (Audio)

2,011 Listeners

WSJ Tech News Briefing by The Wall Street Journal

WSJ Tech News Briefing

1,644 Listeners

Risky Business by Risky Business Media

Risky Business

374 Listeners

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast) by Johannes B. Ullrich

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

650 Listeners

CyberWire Daily by N2K Networks

CyberWire Daily

1,027 Listeners

Click Here by Recorded Future News

Click Here

418 Listeners

Darknet Diaries by Jack Rhysider

Darknet Diaries

8,061 Listeners

Cybersecurity Today by David Shipley

Cybersecurity Today

179 Listeners

CISO Series Podcast by David Spark, Mike Johnson, and Andy Ellis

CISO Series Podcast

191 Listeners

True Spies: Espionage | Investigation | Crime | Murder | Detective | Politics by SPYSCAPE

True Spies: Espionage | Investigation | Crime | Murder | Detective | Politics

1,943 Listeners

Cybersecurity Headlines by CISO Series

Cybersecurity Headlines

137 Listeners

Cyber Hack by BBC World Service

Cyber Hack

1,594 Listeners

Risky Bulletin by Risky Business Media

Risky Bulletin

46 Listeners

The Economics Show by Financial Times

The Economics Show

139 Listeners