ShadowTalk: Powered by ReliaQuest

ShadowTalk: Powered by ReliaQuest

Download on the App Store

ShadowTalk: Powered by ReliaQuest episodes

  • SQLite, Mistral, OpenAI: How AI Attacks Are Reshaping the Attack Surface

    What happens when an AI agent uncovers a zero-day in hours instead of weeks, and state-backed groups are already operationalizing the same tools? With self-hosted AI infrastructure sprawling outside asset registers and supply chain worms reaching inside AI vendors themselves, defenders need a new operating model.

    Join hosts Tehman and John as they discuss: 

    • How an AI agent surfaced a memory-safety zero-day in SQLite
    • How Mini Shai-Hulud reached Mistral AI and OpenAI devices
    • Why the intel-to-action chain still runs at multi-day tempo

    Two questions your organization should be asking right now:

    • Do you have visibility into the shadow AI infrastructure, self-hosted models, and inference endpoints sitting unauthenticated on your network?
    • When high-confidence intel lands, what's your median time from "advisory published" to "response action executed"?

    Resources: https://linktr.ee/ReliaQuestShadowTalk

    John Dilgen: Cyber Threat Intelligence Analyst at ReliaQuest, where he specializes in researching cyber threats impacting ReliaQuest customers. With a strong technical background, he previously served as an Incident Response Analyst and Trainer at ReliaQuest.

    Tehman Tariq: Sr. Manager of Cyber Operations at ReliaQuest. He has spent a majority of my career leading our Incident Response, Security Architecture, and Detection teams. As well has working hand in hand with CISOs to introduce automation allowing for the maturity of their security programs.

    20 min
  • Canvas, Trellix, Mini Shai-Hulud: How Defenders Respond When Supply Chain Attacks Become Weekly

    What's driving the surge in weekly supply chain attacks, and why does the real defender problem start after the supplier gets hit? With 275 million records exposed and 8,809 institutions caught in the downstream fallout, organizations need a new playbook.

    Join hosts Alexandra and John as they discuss:

    • How ShinyHunters abused admin sessions
    • RansomHouse's hypervisor-focused automation
    • How Mini Shai-Hulud compromised 170+ npm packages

     Two questions your organization should be asking right now:

    • Do you have visibility into how trusted vendors authenticate, export, and move your data through native platform features?
    • Are your software pipelines protected against poisoned packages and unauthorized publishing activity in real time?

    Resources: https://linktr.ee/ReliaQuestShadowTalk

    John Dilgen: Cyber Threat Intelligence Analyst at ReliaQuest, where he specializes in researching cyber threats impacting ReliaQuest customers. With a strong technical background, he previously served as an Incident Response Analyst and Trainer at ReliaQuest.

    Alexandra Moore: Manager of Threat Intelligence at ReliaQuest, where she leads intelligence analysis and customer dissemination to help organizations understand and respond to emerging cyber threats. Prior to this, she established and scaled monitoring across Russian-language cybercriminal platforms at Digital Shadows, building collection and analytical coverage to support digital risk protection capabilities.

    32 min
  • Akira, ShinyHunters, and The Gentlemen: Extortion Lessons From Early 2026

    What factors have driven the top ransomware and extortion groups' success in early 2026? And how should organizations structure their defenses to protect against them?

    Join hosts Alexandra and John as they discuss:

    • How Akira is exploiting unknown assets inherited through M&A
    • Why ShinyHunters' vishing and SaaS misconfiguration models work
    • How The Gentlemen grew 588% quarter-over-quarter

     Two questions your organization should be asking right now:

    • Have you run a full asset discovery sweep on every environment inherited through acquisition in the last few years?
    • Do you have automated containment rules in place for anomalous MFA device enrollment and EDR-killing behavior?

    Resources: https://linktr.ee/ReliaQuestShadowTalk

    John Dilgen: Cyber Threat Intelligence Analyst at ReliaQuest, where he specializes in researching cyber threats impacting ReliaQuest customers. With a strong technical background, he previously served as an Incident Response Analyst and Trainer at ReliaQuest.

    Alexandra Moore: Manager of Threat Intelligence at ReliaQuest, where she leads intelligence analysis and customer dissemination to help organizations understand and respond to emerging cyber threats. Prior to this, she established and scaled monitoring across Russian-language cybercriminal platforms at Digital Shadows, building collection and analytical coverage to support digital risk protection capabilities.

    35 min
  • What Happened to Black Basta's Playbook? The Automated Teams Phishing Threat Hitting Executives

    Black Basta disbanded in February 2025, but their playbook didn't go with them. In March 2026, 77% of observed incidents targeted executives and directors, and attackers moved from first contact to malicious script execution in as little as 12 minutes. The tactic has been automated, refined, and is now running faster than most SOCs can respond.

     Join hosts Alexandra and John as they discuss:

    • How attackers leverage Microsoft Teams phishing to target high-privilege accounts with alarming speed
    • Why automation is compressing attack timelines and sharpening target selection
    • The controls that can stop it, from help desk verification to automated containment workflows

     Two questions your organization should be asking right now:

    • When IT requests remote access to a senior leader's endpoint, is identity verified through a channel separate from the one the request came from?
    • Do your highest-privilege accounts have dedicated automated containment workflows — or are they the gap in your response playbook?

    Resources: https://linktr.ee/ReliaQuestShadowTalk

    John Dilgen: Cyber Threat Intelligence Analyst at ReliaQuest, where he specializes in researching cyber threats impacting ReliaQuest customers. With a strong technical background, he previously served as an Incident Response Analyst and Trainer at ReliaQuest.

    Alexandra Moore: Manager of Threat Intelligence at ReliaQuest, where she leads intelligence analysis and customer dissemination to help organizations understand and respond to emerging cyber threats. Prior to this, she established and scaled monitoring across Russian-language cybercriminal platforms at Digital Shadows, building collection and analytical coverage to support digital risk protection capabilities.

    27 min
  • Did ShinyHunters Compromise Vercel? Every CISO's Cloud Security Visibility Problem

    89% of organizations that suffered a SaaS breach last year believed they had appropriate visibility. They had the logs — what they lacked was detection on what mattered. The Vercel incident shows exactly how costly that gap can be.

     Join hosts Brandon and John as they discuss:

    • How a third-party OAuth chain may have exposed Vercel's internal data
    • Why SaaS visibility gaps leave organizations exposed
    • The controls that can break the attack

    Resources: https://linktr.ee/ReliaQuestShadowTalk

    John Dilgen: Cyber Threat Intelligence Analyst at ReliaQuest, where he specializes in researching cyber threats impacting ReliaQuest customers. With a strong technical background, he previously served as an Incident Response Analyst and Trainer at ReliaQuest.

    Brandon Tirado: Director of GreyMatter Operations for ReliaQuest. Brandon is a skilled cyber defense professional with a unique combination of management and hands-on experience. With a deep understanding of adversary motives and the tactics, techniques, and procedures (TTPs) they use to achieve their goals, Brandon enjoys operationalizing his knowledge to make it more difficult for adversaries to operate within the environments of ReliaQuest customers. His managerial and hands-on experience enriches ShadowTalk with practical and strategic viewpoints. 

    26 min
  • What Claude Mythos Means for Organizations

    Resources: https://linktr.ee/ReliaQuestShadowTalk

    Join hosts John and Alex, alongside special guest and ReliaQuest CTO Joe Partlow, as they discuss:

    • How Claude Mythos autonomously generated exploits
    • Why AI is accelerating CVE volume
    • Defense strategies organizations need now

    Joe Partlow: CTO of ReliaQuest, a leading Information Security provider and is currently involved with new product initiatives along with research and development efforts. Joe has been involved the Information Security field for over 30 years, in both the defensive side and offensive capabilities. Current projects include data ingestion/analytics at scale, DFIR automation and generative AI. He is also a regular speaker and contributor at security conferences, groups and associations. Joe has a degree in Computer Information Systems and holds many industry-specific certifications

    John Dilgen: Cyber Threat Intelligence Analyst at ReliaQuest, where he specializes in researching cyber threats impacting ReliaQuest customers. With a strong technical background, he previously served as an Incident Response Analyst and Trainer at ReliaQuest.

    Alexandra Moore: Manager of Threat Intelligence at ReliaQuest, where she leads intelligence analysis and customer dissemination to help organizations understand and respond to emerging cyber threats. Prior to this, she established and scaled monitoring across Russian-language cybercriminal platforms at Digital Shadows, building collection and analytical coverage to support digital risk protection capabilities.

    26 min
  • Axios and Trivy — Supply Chain Gaps Organizations Must Fix

    Resources: https://linktr.ee/ReliaQuestShadowTalk

    Join hosts John and Tehman as they break down two of the most consequential supply chain attacks of 2026:

    • How DPRK actors socially engineered a NPM maintainer
    • Why hijacked GitHub versions are a CI/CD wake-up call
    • The three gaps every security team needs to close

    John Dilgen: Cyber Threat Intelligence Analyst at ReliaQuest, where he specializes in researching cyber threats impacting ReliaQuest customers. With a strong technical background, he previously served as an Incident Response Analyst and Trainer at ReliaQuest.

    Tehman Tariq: Sr. Manager of Cyber Operations at ReliaQuest. He has spent a majority of my career leading our Incident Response, Security Architecture, and Detection teams. As well has working hand in hand with CISOs to introduce automation allowing for the maturity of their security programs.

    25 min
  • Faster, Smarter, and Already Escalated — What It Takes to Defend Against the Modern Threat Landscape

    Resources: https://linktr.ee/ReliaQuestShadowTalk

    Join hosts Alexandra and John, live from Exponent 2026, alongside top security leaders as they discuss:

    • How organizations keep pace with attackers
    • Why one in four incidents starts with social engineering
    • How automated response is helping organizations

    Chris Thompson: CISO of Caris Life Sciences, a leading, next-generation AI TechBio company and precision medicine pioneer.  Chris is a retired Federal Agent having most recently led the North Texas Cyber Task Force for the FBI and was an operator on the FBI Cyber Action Team.

    Michael Andreano: Sr. Director of Information Security at Hikma Pharmaceuticals, leading their global information security team.  He has over 30 years experience in the healthcare and hospitality industries with roles of increasing responsibility at Merck, Wyndham Hotels, Olympus, Syneos Health, and now Hikma the past four years.  He also is part of the Evanta C-Suite Information Security Community where he serves as a Governing Body member and active in his local Cloud Security Alliance chapter in Lehigh Valley, Pennsylvania. 

    John Dilgen: Cyber Threat Intelligence Analyst at ReliaQuest, where he specializes in researching cyber threats impacting ReliaQuest customers. With a strong technical background, he previously served as an Incident Response Analyst and Trainer at ReliaQuest.

    Alexandra Moore: Manager of Threat Intelligence at ReliaQuest, where she leads intelligence analysis and customer dissemination to help organizations understand and respond to emerging cyber threats. Prior to this, she established and scaled monitoring across Russian-language cybercriminal platforms at Digital Shadows, building collection and analytical coverage to support digital risk protection capabilities.

    34 min
  • The Invisible Attack Surface: Iran-Aligned Threat Actors and Corporate Blind Spots

    Resources: https://linktr.ee/ReliaQuestShadowTalk

    Join hosts Brandon and John as they discuss:

    • How Handala wiped 200,000 devices by weaponizing a trusted platform
    • Why your organization doesn't need to be a direct target to be at risk
    • How AI-enhanced malware is helping attackers get faster

    John Dilgen: Cyber Threat Intelligence Analyst at ReliaQuest, where he specializes in researching cyber threats impacting ReliaQuest customers. With a strong technical background, he previously served as an Incident Response Analyst and Trainer at ReliaQuest.

    Brandon Tirado: Brandon Tirado is the Director of GreyMatter Operations for ReliaQuest. Brandon is a skilled cyber defense professional with a unique combination of management and hands-on experience. With a deep understanding of adversary motives and the tactics, techniques, and procedures (TTPs) they use to achieve their goals, Brandon enjoys operationalizing his knowledge to make it more difficult for adversaries to operate within the environments of ReliaQuest customers. His managerial and hands-on experience enriches ShadowTalk with practical and strategic viewpoints. 

    20 min
  • The 2026 Annual Threat Report Breakdown, Part 3: The Long Game — Nation-State Threats & What's Coming in 2026

    Resources: https://linktr.ee/ReliaQuestShadowTalk

    Join hosts John and Alex as they discuss:

    • How a Chinese APT maintained access for over a year
    • Why North Korean impersonation surged 116%
    • Why attackers exploit the same foundational gaps

    John Dilgen: Cyber Threat Intelligence Analyst at ReliaQuest, where he specializes in researching cyber threats impacting ReliaQuest customers. With a strong technical background, he previously served as an Incident Response Analyst and Trainer at ReliaQuest.

    Alexander Capraro: Alexander Capraro is a Cyber Threat Intelligence Analyst at ReliaQuest with over five years of experience in cybersecurity. With his prior experience as a Security Analyst, he specializes in incident response, malware campaign tracking, and OSINT investigations. 

    26 min

About ShadowTalk: Powered by ReliaQuest

From the publisher's feed

Want to hear what industry experts really think about the cyber threats they face? ShadowTalk is a weekly cybersecurity podcast, made by practitioners for practitioners, featuring analytical…

More shows like ShadowTalk: Powered by ReliaQuest

Hacked by Hacked

Hacked

193 Listeners

Security Now (Audio) by TWiT

Security Now (Audio)

2,011 Listeners

WSJ Tech News Briefing by The Wall Street Journal

WSJ Tech News Briefing

1,644 Listeners

Risky Business by Risky Business Media

Risky Business

374 Listeners

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast) by Johannes B. Ullrich

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

650 Listeners

CyberWire Daily by N2K Networks

CyberWire Daily

1,027 Listeners

Click Here by Recorded Future News

Click Here

418 Listeners

Darknet Diaries by Jack Rhysider

Darknet Diaries

8,061 Listeners

Cybersecurity Today by David Shipley

Cybersecurity Today

179 Listeners

CISO Series Podcast by David Spark, Mike Johnson, and Andy Ellis

CISO Series Podcast

191 Listeners

True Spies: Espionage | Investigation | Crime | Murder | Detective | Politics by SPYSCAPE

True Spies: Espionage | Investigation | Crime | Murder | Detective | Politics

1,943 Listeners

Cybersecurity Headlines by CISO Series

Cybersecurity Headlines

137 Listeners

Cyber Hack by BBC World Service

Cyber Hack

1,594 Listeners

Risky Bulletin by Risky Business Media

Risky Bulletin

46 Listeners

The Economics Show by Financial Times

The Economics Show

139 Listeners