POPULARITY
Nosipho Radebe speaks to Tony Anscobe, Chief Security Evangelist at ESETSee omnystudio.com/listener for privacy information.
Wil Santiago, Wil Santiago, chief security and trust officer at Blackpoint Cyber Wil Santiago, chief security and trust officer at Blackpoint Cyber, joins In The Channel to discuss the findings of the company’s 2026 Annual Threat Report – research grounded in thousands of real incidents investigated by Blackpoint’s security operations centre, not surveys. The headline finding: attackers are no longer trying to break in. They’re logging in. Using stolen credentials and commodity remote management tools, threat actors are walking through the front door, hiding in plain sight, and operating with system-level privileges – sometimes for days before anyone notices. Santiago walks through the key trends the SOC identified across 2025: ClickFix and fake CAPTCHA campaigns accounted for more than half of all identifiable incidents, with attackers abusing trusted infrastructure including Azure Blob storage and Cloudflare to deliver payloads. RMM abuse showed up in roughly 30 per cent of triaged incidents – threat actors installing their own version of the same tools MSPs use legitimately, then living off the land with god-mode access. And Adversary-in-the-Middle attacks are now routinely hijacking authenticated sessions even when MFA is in place, by abusing OAuth token handling. The conversation also covers Blackpoint’s detection philosophy: behavioral context over malware signatures. Understanding what normal looks like in an environment – who uses what tool, at what time, from where – is what allows the SOC to catch attackers before they act. It’s a philosophy that is producing results: Blackpoint disrupted 56 per cent of incidents before a payload was ever deployed. Santiago’s closing recommendation for MSPs is straightforward: start with an RMM audit. Know every remote management tool deployed across every endpoint and server you manage. You cannot protect what you don’t know exists. The 2026 Annual Threat Report is available for download on the Blackpoint Cyber website. Read Full Transcript Robert Dutt: Hello and welcome to In The Channel from ChannelBuzz.ca, bringing news and information to the Canadian IT channel community for the last 16 years. I’m Robert Dutt, editor of ChannelBuzz.ca and your host for the show. Wil Santiago is Chief Security and Trust Officer at Blackpoint Cyber, an MDR provider whose SOC monitors and responds to threats in real time across a large base of MSPs and their clients. And unlike a lot of threat research that’s survey-based or derived from external reporting, what Blackpoint publishes comes from live incident data, thousands of actual threat responses they’ve worked through in the SOC. Their 2026 annual threat report has a thesis that cuts right through it. Attackers are no longer trying to break in, they’re logging in, using stolen credentials and legitimate IT tools, the same RMMs, the same cloud platforms that MSPs rely on every day, to walk through the front door, hide in plain sight, and work their way towards payday. It’s a theme we’ve been tracking at ChannelBuzz.ca. If you caught our conversation with Tony Anscombe from ESET, that one dug into the mechanics of how MSP tools are being weaponized against the very clients they’re supposed to protect. This conversation is the data layer behind that story, and the detection philosophy that Wil and the Blackpoint team have built to counter it. Their SOC is disrupting 56% of incidents before a payload even deploys. We talk about how. Let’s get right into it. My chat with Wil Santiago. Wil, thanks for taking the time, I appreciate it. Wil Santiago: Thank you, Robert. Robert Dutt: For people who know Blackpoint primarily as an MDR provider, but maybe haven’t dug into the research side, can you give us a quick sense of what your SOC is actually seeing day to day? When you say this report is based on thousands of real incidents, what does that mean in practical terms, in terms of how you gathered this data? Wil Santiago: That’s a great question, Robert. It really starts at the core of what we focus on at Blackpoint Cyber. In 2025, we focused a lot of our detection efforts in the cloud endpoints, but what we realized is that at the core, at that identity layer, that’s the most important thing. But what we’re protecting at Blackpoint is the identity. What we observed in 2025 is this interesting shift where, yes, there’s vulnerabilities, there will continue to be vulnerabilities. However, threat actors don’t necessarily need to weaponize those vulnerabilities to gain access into an environment. They’re not really targeting customers or companies with any specific new zero-day technology or exploits that are novel. They’re just logging in using stolen passwords. We’re still at that pivotal point, but we’re still talking about the same things we’ve been talking about, password reuse, making sure you’re protecting yourself from phishing emails, so on and so forth. But the reality is that threat actors are getting in. They’re stealing credentials and they’re using legitimate tools to just log in, walking through the front door. Robert Dutt: Yeah, the headline from the report was very catchy with the attackers are no longer trying to break in. They’re just logging in, as you say. And that framing echoes what we’ve seen in other reports elsewhere. People are calling 2025 the year of the abuse of trust in terms of security trends, but your numbers are operational and not survey-based. I’m curious what trusted compromise looks like from where you sit. Is there really a shift away from what you were seeing a couple of years ago or three years ago, or has this always been the playbook and we’re only now measuring it properly? Wil Santiago: Yeah, so if I compare back to, let’s say, 2022, I think we at Blackpoint would still see a trend, the threat actors gaining access into an environment, usually using some type of exploit at that time. You can point to a number of Microsoft Exchange exploits that happened during that time. The Hafnium group was doing a lot of Exchange exploits. The reality is there came a certain time where we were detecting Cobalt Strike, a malware commodity tool, every single day in Blackpoint Cyber’s SOC. And then eventually it became once a week, and then it became once a month. So then we started to think, well, what’s happening with the shift of tactics with the threat actors? And what we found is instead of installing Cobalt Strike, they started to install legitimate IT tools. And that’s the trust component. When they’re installing tools that you use internally, they now can abuse those tools the same way that you use those legitimately. And so we have these threat actors that not only are abusing legitimate tools, but like I said, they’re abusing legitimate identities. So when you have what I call the keys to the kingdom, the passwords, I am you. I am now Robert, for all intents and purposes for this sort of webinar. I think the interesting part that we’ve seen at Blackpoint is that threat actors have really, really focused on leave-behinds. And those leave-behinds are commodity remote management tools. Why do they do that? Because EDRs don’t know how to detect them as malicious, right? These are legitimate IT tools that are being used to service MSPs and their customers. And a threat actor just installs their version of the same exact tool that you’re using legitimately. Right? And so the trust component is you go to review your assets and you see ScreenConnect installed in your environments because you use ScreenConnect, right? But then when you start taking a closer look, you start to realize, wait a second, there’s four different ScreenConnect IDs on this one machine. Now we have a more of a problem, right? And so the attack is a little bit of an invisible signature detection because it’s an authorized tool, right? And so we really have to get to this layer of identifying threat actor activity with behavior context. If you’re an AnyDesk shop, then why do you have TeamViewer installed on your file server that’s publicly facing, right? Let’s start to ask those questions and dig into that a little bit. Robert Dutt: Your SOC found that fake CAPTCHA and ClickFix campaigns accounted for, I think it was 50-odd percent of identifiable incidents. That’s a majority of attacks being driven by a technique that essentially requires the victim to step on the link to execute it themselves. Why is that scaling so fast right now? And especially for an MSP who tends to think, you know, my technicians are too smart to do that. What’s kind of the honest answer for what they need to be looking for and protecting against? Wil Santiago: Yeah. And, you know, ClickFix is such an easy attack when you really get into the root of what it does. But it starts with social engineering. You’re enticing someone, again, just like with phishing, to visit something that you’re going to tell them to do an action. And most of the time, they’re going to do that action. Now, why this is so effective is we’re seeing techniques that really enable the threat actor to deliver the payload. And how do they do that? Search engine optimization, right? These SEO links at the top, when you go look for an OBS installer, because you need your camera to look well, or you get a Google sponsor result. Threat actors are just buying those sponsored results and delivering their payloads on there. You click on it thinking you’re going to download OBS, and then it tells you, hey, wait a second, you have to make sure that you are human. Verify that we’re used to verifying we’re humans to download something. So we go and we click it. But then it says, hey, open up your Windows Run command and maybe run this command on us, on your computer for us. And what happens? Threat actors go and they put the commands on a website. They have this watering hole spread out all throughout infrastructure that’s globally distributed. Google, Microsoft, all these sort of cloud infrastructure hosting providers that exist. Threat actors use those. So when you’re looking at your firewall logs and you’re seeing your internal team going to Microsoft.com, hey, it’s Microsoft, right? But the reality is, it’s likely an Azure Blob site that’s just being hosted on Microsoft, that is a threat actor that’s actually hosting it. And so they’re abusing that trust function to say, hey, you need this OBS installer. You Googled it. I didn’t tell you to go Google that. You were the one that did that. And then they found my link, which I posted a malicious payload there. And so again, that abuse factor is all the things we’ve taught our employees, our customers, our MSPs to do, right? Go to Google, make sure you identify the link. Make sure you look for Microsoft. Make sure you see the end of a URL or domain. Validate that. Well, the adversary goes, okay, they want to play that game. I’m just going to host this on Cloudflare. And now we’re back to this gate where now someone clicks on something. Well, what’s this Cloudflare? That’s a legitimate service. I know that to be true, right? It’s very true. The reality is the infrastructure is very, very easy to set up. And it doesn’t require a lot of action. It just requires someone to take a command and put it on their machine. And all the background work happens in the background, right? And so beyond that, we used to see a lot of threat actors use this sort of technique to download malware onto machines. But again, going back to what I mentioned about RMMs, now they’re just downloading an RMM. And that just looks like a legitimate process to an EDR. Robert Dutt: Right. So for an MSP, especially when training or making sure their technicians are aware, is it just as simple as making sure they’re aware of this threat landscape and this wrinkle in it? Or is there something more that’s sort of the advice there on how to protect yourself as best you can? Wil Santiago: That’s a great question. And really, you know, I would say any MSP watching this show, starting today or tomorrow, the first thing that I always tell people, audit your RMM inventory. Asset inventory is the number one thing that customers should be doing, right? You cannot protect what you don’t know exists. And so every single remote management tool that’s deployed across every endpoint you manage, every server you manage, you need to audit those, right? Like you’re giving direct access to a system. And most of the time, those RMMs run in the system context, which means they have the permissions and privileges of any admin, right? And now you have this adversary that has a foothold. They can deploy tools using admin privileges and permissions. So you have to audit your RMM inventory, right? Making sure that you understand what’s happening across those production servers. And forcing MFA, that’s a big one. We see a lot of incidents that source from RMM abuse because they log into the MSP’s RMM console, the cloud-based consoles. Some of those don’t have MFA involved. Again, keys to the kingdom, MFA everywhere, that needs to be a reality. Then we need to start moving into what I call more resilient engineering, right? Conditional access policies, preventing individuals from logging in from untrusted sources, locations, right? There’s ways that you can lock down access to an RMM and assume a threat actor is able to steal credentials because they maybe installed an info stealer on a user’s machine, stole their browser credentials. They reuse the same credentials for Gmail that they do for their corporate environment. Well, now a threat actor just perusing finds their credentials and says, “Oh, I’ve got IT Glue permissions now. I’m going to go log into this and restore all these configs in IT Glue or whatever tools out there.” Well, now the threat actor has access to that. And so that’s how they’re pivoting across these environments. They’re going from cloud to on-prem, on-prem to cloud. One of the things that we caught at Blackpoint recently, and this was a really cool response, but the threat actor compromised the cloud environment first. They then took that cloud access, deployed an RMM using Intune to the devices, and then they used that on-prem access to go to those machines and do their own work directly from that console. I called it overkill. They didn’t have to do that because they had the cloud environment. But because they did that, that sort of prompted this investigation for this MSP to approach us and say, “Hey, we believe something is happening. We investigated and quickly saw the Intune process was the responsible process for deploying some of this malware. So we told them, “Hey, deploy our cloud response suite. We want to understand what’s happening in your cloud.” And sure enough, seven global admins were compromised. So again, limiting scope is important here, right? Least privilege. Why do we have so many people with admin privileges and permissions? I think there’s 192 admin roles or something like that in Microsoft, but we default to just, you get global admin, you get all the permissions. And so now an adversary compromises a Microsoft 365 tenant. Well, now they have the permissions of a global admin. And unfortunately for us, when we shifted from the on-prem strategy to the cloud strategy, we just started pushing everything in the cloud and we say, “Oh, it’s fine. It’s in SharePoint.” We didn’t realize though that that’s only being protected by a password and an MFA token, both of which can be stolen, right? So the protection is not really there. That’s why we have to move to that resilient engineering. And so it’s moving from that reactive alerting to that posture alerting, right? Why is someone trying to log in from France? We have nobody in France. Robert Dutt: So your report showed almost a third of triaged incidents involved RMM abuse. And that’s something, that kind of trend line is something that we’ve seen in other reports. You know, one of your peers is talking about a 200 plus percent spike in abuse of RMM in attacks. I’m curious, especially since you’re sitting in the SOC there, what does RMM based intrusion actually look like in the SOC here? You know, I’m guessing curious, is there a moment where it’s genuinely hard to tell, you know, is this actually a tech doing a routine task or is this an attacker? And if so, what kind of breaks the tie and causes you to go, “No, no, that’s not right.” Wil Santiago: Yeah. Well, there’s kind of two ways to look at it, right? We have threat actors that are compromising MSP RMM tools. These are tools that are owned, managed by the MSP. They’re usually protected with some cloud login, whether they self-host it or they have the vendor host it for them. Threat actors can log into those systems with a password and a username, right? So we see a lot of brute forcing of those systems, especially if they’re self-hosted systems, they usually don’t have the protections of the vendors. They don’t put a WAF in front of them. And so they’ll try to brute force them and just log in, right? Those are few and far between, to be quite honest. We don’t see those as often, but what we do see often is, again, they gain access into an environment, usually by compromising a VPN. Now they’re on the network. Now they can move throughout that network as they’re on the VPN, and they’ll usually find a foothold. And if they have a credential like a local admin, they’ll take that one foothold and then they’ll distribute their RMM across that entire fleet of the network with one command from that foothold. So for us, when we’re looking at RMM deployments, MSPs deploy RMMs in a certain manner and format. They’re not deploying an RMM at two o’clock in the morning on a Saturday when they’re a US-based company. And oh, by the way, they just logged in from a Chinese-based IP, right? So again, there’s indicators that are very clear cut of like, okay, this deployment of RMM tools absolutely malicious. Most of those cases come to the case of, you know, we have application control within Blackpoint that allows us to alert when someone is installing a new application that’s unauthorized. And so what we tell our MSPs to do is, hey, set up your policies that if you’re a Ninja RMM shop, you cannot have any other installations of any other RMM. ScreenConnect is not going to be involved. And so that allows us and affords us the ability to do is, when we get that alert that says someone’s attempting to install a ScreenConnect, we can go back and sort of recreate the path of how do they get here. And what that allows us to really get into is, again, that response, right? And that response is preventing the installation of the RMM, eradicating the threat actor by isolating the machine, making sure you remove their footholds, getting those SSL VPNs off of the public facing internet, and having that exposure management reduced, right? And so when we look at RMM abuse in practice, once they get that RMM installed, again, they’re living off the land with system privileges. System privileges is something that most people tend to understand, but it’s just keys to the kingdom. You are God mode at that point. You can do whatever you feel to deploy and ultimately spread your access with that level of access, right? And so they’ll use it for backdoors. And oftentimes, they may compromise the environment and say, “You know what? I’m busy.” We’ve actually seen this over the holidays where they go take their breaks. Just like everyone else does. It’s Christmas. I’ve done a lot of hacking. So they leave their leave-behind tools and they come back. That’s their access factor. Again, it’s one of those things where they’re hiding in plain sight. Robert Dutt: You touched on MFA a little while ago and the report flagged the use of adversary-in-the-middle attacks. AiTM attacks that let threat actors hijack authenticated sessions, even when the MFA is there. So I guess what’s the message to MSPs who are thinking, “All right, if we just get MFA everywhere, we’re good, we’re covered.” Wil Santiago: Token protection, right? MFA is great. You have to have it. But understand that there’s flaws in the way that MFA communicates to servers. And so the whole way that an adversary-in-the-middle attack works is by abusing OAuth. And OAuth is a standard protocol of just making sure that we understand how systems should communicate for authentication. And what’s really nice about that is we can take that offensive research and then make defensive practices towards that. And so token protection is really huge there. There are a lot of built-in protections in Microsoft that allow you to invalidate session tokens after a certain period of time. Every hour you could refresh these tokens. You now, again, when you get to this resilient engineering, you start to push the adversary to be a little bit more aggressive. And that’s your detection mechanism. When you allow an adversary to move unfettered throughout a network, they’re going to move unfettered throughout a network. But the moment that you give them that sort of, “Eh, stop here. Let me see your ID.” Then they start to get a little uneasy. They’re like, “Wait a second. I don’t know how to move anymore.” And so specifically in MFA, when we talk about session hijacking and session tokens, the token protection aspect is really important because that’s a conditional access policy that you can implement. And most people do not implement those conditional access policies. Now, there’s a slew of them that work in conjunction with each other. But the idea here is your tokens will likely be compromised at some point. If you are duped into clicking one of these phishing links, it’s very easy to steal a session token. So we have to move past that. Now that we know that’s going to happen, how do we prevent the adversary from actually using those session tokens successfully? And that’s where invalidating the sessions comes in, having the session protection, conditional access policies, protected devices, things of that sort. That prevents them from being able to use those session tokens. Robert Dutt: A stat that I keep looking at in the report was that you guys managed to disrupt in the SOC 55, 56 percent of incidents before a payload was deployed. It’s a real number. That’s pretty significant. I guess what is disrupted before the payload hits mean operationally? And what does it tell us about where the detection opportunity actually lives? Because it sounds like the window isn’t did malware execute? It’s something a lot earlier. Wil Santiago: That’s exactly right. When we look at the cyber kill chain, we want to start pushing our adversaries as far left of boom as possible. Right. And so when you hear about this whole right of boom concept, basically, you’ve met your match. And now boom, you’ve now been impacted. Right. And so there’s a lot of indicators of compromise that we can start to hone in on. That will give us an understanding of whether this is legitimate or illegitimate. Right before an adversary even types the command. And again, that’s the context. And the context is what the SOC is really understanding of a customer. Where do they operate? What are their hours of operation? Where are they globally distributed? What’s the infrastructure they use? What are the tools they use? How did they use those tools? Did they deploy tools every Thursday at 2 p.m.? So there’s this constant checklist that they’re doing every single day to understand this. And so when we talk about living off the land, threat actors are trying to execute commands. Right. They’re just trying to sit there. We’re typing on a keyboard command line. Hey, I’m not going to introduce any new factors to my intrusion. I’m just going to live off the land. Ultimately, they want to deploy a payload at the end of all of that. But if they deploy a payload too early in their kill chain, they risk getting caught. Right. And so what they’ll do is they’ll stage everything. They’ll compromise an endpoint. They’ll add a persistent backdoor user. They’ll deploy some small scripts to enumerate the network. Just to get an understanding of what’s happening. But they’ll usually stage those in like a C:UsersMusic folder. And that’s their staging environment. So you can catch them. And we’ve caught at Blackpoint a number of threat actors where their toolkits are still on the machine because we caught them so early left of boom that legitimately all they did was log into a machine, try to mount a share, but it failed. And then that failed share mount is like, wait a second. They have never tried to mount a share on this file server ever. And then you call the MSP and they’re like, yeah, Monday through Friday, our hours are from eight to three and it’s seven p.m. at Thursday. Right. Well, now the context of the intrusion starts to become a little bit more apparent. And so we have to do this very quickly. The reality is for us, behavioral context, it matters more than ever. That is the true bread and butter for stopping threat adversaries is understanding the behaviors in the context of which they employ to compromise the network or compromise an endpoint. And so we focus a lot of our threat intelligence and our adversarial intrusion analysis based off of what hack or tradecraft is. We always say this internally, you cannot protect what you don’t know how to hack. So we spend a lot of our time recreating these attacks, understanding where do we catch them? And one of the things that we found is in those early development cycles of understanding the behaviors of an adversary, we found key indicators of like, wait, that is a very high fidelity indicator that before an adversary even gets on a keyboard, we’ve already caught them. They don’t know that yet. Right. And so that’s a little bit of our secret sauce there. But the reality is that secret sauce was created because we thought like threat actors and we sort of recreated what they did in controlled environments and testing environments to then to make sure the detection and the efficacy of what they’re doing is caught within our product. Robert Dutt: So this is a bit of a sidebar, but it was a new term, at least to me. You flagged Etherhiding in the report, attackers embedding malicious logic and blockchain smart contracts to manage compromised sites. Can you walk me through that real quick? And how real is this in terms of how widely it’s being deployed today? And why does it matter for detection purposes? Wil Santiago: It’s a newer term. You know, I would like to say that we have way too many terms in security and security, you know, sort of like we’re trying to be cool. The reality is this is a technique that leverages transactions on a public blockchain to basically retrieve malicious payloads. Right. And so this is another sort of trend that an adversary is using where they’re just retrieving a payload from something that is trusted. In this case, cryptocurrency. A lot of people trust cryptocurrency. A lot of people trust public blockchains. And so the idea here is that, you know, threat actors are usually going to utilize some type of social engineering and then that social engineering is going to get you to come to like a WordPress site through that WordPress site. They’re going to basically have scripts that you’re going to download and ultimately run. Innocuously. Now, when that happens, you download something that you think is OBS, like the example I gave earlier, it’s actually a JavaScript payload. Well, that JavaScript payload goes and reaches out and it pulls a malicious payload from the ether blockchain. Right. And so that’s that aspect of there’s function calls that we’ve identified within Blackpoint that are related to that remote management of pulling payloads from that blockchain. My personal opinion of this sort of technique is, you know, it gives a lot of advantage to the threat actors in terms of stealth and flexibility. But it is one of those techniques that is complicated for majority of what we see at Blackpoint. Most threat actors are not getting to that complicated level of compromising. They’re just hosting malware on a compromised WordPress site of a legitimate company that they’ve co-opted the passwords for. Right. And again, we see threat actors from different angles. 90 percent of what we see sort of today is cybercrime related. Right. So you have a lot of the fake CAPTCHA, the ClickFix lures, the Etherhiding stuff. The reality is at the end of that payload, we see everything from Etherhiding to Cobalt Strike to ransomware and compromise. The way that they get to that sort of compromise is kind of the same, though. Robert Dutt: Last one for me, if an MSP is listening to this and they’ve just absorbed that, you know, more than half of the attacks they’re going to see start with legitimate credentials, their own tools are showing up in about a third of incidents. MFA isn’t necessarily a guarantee. Where do you start? You know, what’s the one thing they probably aren’t doing today that would meaningfully move the needle for them in terms of making sure things are as locked down, as protected as is possible? Wil Santiago: That’s a great question. I like to say we should probably be spending most of our time right now really focusing on posture and posture management, reducing the attack surface. Right. How do you how do you start? Where do you start reducing the attack surface? This is where frameworks really come into play. And there’s some really great frameworks that are really prescriptive out there. One of them is the Center for Internet Security Controls, CIS version 8.1. It’s very prescriptive and it starts from the very top, right? External facing assets and applications. How do you lock those down? Cloud assets and applications, internal assets, user accounts, passwords, right? And it gives you a prescriptive way to deal with incidents. Beyond that, there’s kind of this like practical implementation groups that they have, right? And so you can start by implementing the CIS Controls with implementing one Implementation Group, right? You don’t have to implement them all. And so I think there’s a subset of Implementation Groups that can be used, but it’s about identifying, you know, what of these sort of subset groups will really resonate with your organization and your maturity level, right? And so I tell most people, look at IG1, start with the essentials. If you’ve already fit the bill on that, then move to IG2, right? But the reality is IG1 is going to give you that foundational security for organizations. And then IG2 and IG3 are going to be a little bit more advanced for more complex things. Most people are probably in that IG1, but they probably could benefit from some of the things in the IG2, the Implementation Groups there. That’s really going to help you really target your defenses against ransomware. That’s going to help you sort of approach a risk-based approach. That’s another thing that, you know, all risk is not the same, right? Risk is treated differently. And it’s important for anyone running a security team to help understand how should I prioritize my risk, right? Where is my risk going to really give me issues if a threat actor gets into it? And therefore, I always say, start there. We all know what keeps us up at night. So that’s the areas that we need to focus on. Robert Dutt: All right. Some sage advice and some sobering numbers as well. I appreciate your taking the time and walking us through some good stuff. Wil Santiago: Thank you, Robert. I really appreciate it. Robert Dutt: There you have it. Wil Santiago from Blackpoint Cyber. I’d like to thank Wil for his time today and for bringing some real energy to what can sometimes be pretty dense subject matter. And of course, I’d like to thank you for listening. The data in this conversation is worth thinking about. More than half of the attacks Blackpoint’s SOC starts with someone simply logging in, using credentials that were stolen sometimes long ago, and that users are still reusing across platforms. A third of triaged incidents involve RMM tools, the same tools your techs are using right now to manage endpoints. And MFA, as much as we’ve come to rely on it, is no longer the finish line it once appeared to be. The antidote Wil describes is behavioral context, understanding what normal looks like in an environment so you can spot when something legitimate is being done illegitimately. Not “Is this malware?” But “Is this person, using this tool at this hour from this location, doing something they’ve never done before?” That’s a fundamentally different way about thinking of detection, and it’s why the human element in the SOC still matters. And I’ll add one thing that Wil mentioned after we wrapped the recording. It’s a dimension of this fight that doesn’t get talked about often enough. Blackpoint’s work doesn’t stop at detection and response. They’re actively working to identify and disrupt adversary infrastructure, notifying law enforcement, including, he noted, Canadian authorities, with the specific goal of making cybercrime economically painful. The logic is straightforward. If your infrastructure gets taken down every time you try to run a campaign, the math of operating a criminal enterprise starts to change. That’s offense, and it sounds like they’re playing it. If you’re finding the show valuable, I’d encourage you to follow or subscribe to the podcast. You can find us on Apple Podcasts, Spotify, YouTube, all the major directories. A rating review always helps. Until next time, I’m Robert Dutt for ChannelBuzz.ca, and I’ll see you in the channel.
Umelá inteligencia sa vo firmách čoraz častejšie stáva bežnou súčasťou práce, keďže dokáže automatizovať úlohy aj spracovať veľké množstvo informácií. Zároveň však prináša nové riziká. Podvody sú presvedčivejšie a útoky vedia byť automatizované. Ako teda využívať umelú inteligenciu bezpečne? Ako menia kybernetické hrozby? A prečo je dôležité budovať si v tejto oblasti ako firma aj vlastné know-how? Aj o tom sa v Indexe zhovárala Eva Frantová s Kamilom Pšenákom, produktovým manažérom spoločnosti ESET, s ktorej podporou vznikla aj táto časť Indexu. See omnystudio.com/listener for privacy information.
(Presented by Thinkst Canary: Most Companies find out way too late that they've been breached. Thinkst Canary changes this. Deploy Canaries and Canarytokens in minutes and then forget about them. Attackers tip their hand by touching 'em giving you the one alert, when it matters. With zero admin overhead and almost no false-positives, Canaries are deployed (and loved) on all 7 continents.) Three Buddy Problem - Episode 107: Proofpoint's Greg Lesnewich joins the show to break down Laundry Bear, the "half-click" webmail exploits that let a Russian GRU cluster hack inboxes the moment an email was opened, and what it took to publish alongside the NSA, FBI and sixteen allied agencies. Plus, Anthropic and OpenAI both admit their models escaped test sandboxes and popped real companies, why JAGS wants the CFAA burned down and vulnerable devices bricked, and a heartfelt detour into how threat hunters actually build intuition and skills. Cast: Greg Lesnewich, Juan Andres Guerrero-Saade, Ryan Naraine and Costin Raiu. Timestamps: 0:00 Sponsor - Thinkst Canary 1:34 Greg Lesnewich introduces the Proofpoint threat-hunting team 5:23 Inside the NSA ‘Laundry Bear' advisory 7:15 What does "half-click" mean? 9:58 Laundry Bear's Zimbra exploit: DNS exfil and app-specific password persistence 12:59 Ferrari model numbers, F1 UNC names, and ESET's Operation RoundPress 17:05 Targeting Ukraine, US universities, and magnetic fusion research 19:34 How threat hunters actually build intuition 32:35 Systems thinking, Donella Meadows, and Costin's laptop under the dinner table 54:48 The dopamine hit of a real find and the deleted "never mind" messages 1:00:42 Magnets of threats: under 1% of customers ever see an APT 1:25:21 Getting detections into the product, and coordinating a release with NSA 1:53:22 Anthropic and OpenAI models breaking out of the eval sandbox 2:17:45 The case for killing the CFAA and bricking vulnerable devices 2:43:44 AI in the lab, malware paleontology, Google's new names, and AngrySpark
Entrevista con Alexander Ramírez Duque, CEO de Frontech - ESET Colombia by LA PATRIA
Send us Fan MailIn this episode of Partnerships Unraveled, we sit down with Michal Jankech, Vice President of Enterprise, Small Business, and Managed Service Provider Segments at ESET. With 16 years at ESET, a first decade in product management, and a strategic advisory role shaping how the company evolves, Michal brings rare depth across both technical and commercial perspectives to a conversation about what actually builds durable partnerships.Michal opens with the story of how a decade in product management shaped his approach to partner strategy. Traveling with clients as a product manager showed him something that still holds: many cybersecurity decisions are partner-led, and the strongest relationships between vendors and technical partners are built engineer to engineer. That foundation now feeds his advisory work with the CEO on how to steer the company through change. In a matrix organization the size of ESET, influence beats authority, and driving transformation depends on relationships, belief, and a clear, consistent story everyone across the business is willing to carry.From there, the conversation turns to ESET's evolution ahead of its 40th anniversary. The company has been quietly using machine learning in detection long before it was called AI, and the current moment brings new relevance to that engineering-first heritage. Michal shares how perception matters as much as substance, and how the company is modernizing its communication to match what it delivers. He also gets into where data sovereignty is landing for European buyers today. As a fully European vendor with all core processing on the continent, ESET has turned a former disadvantage into a real differentiator.Michal closes with the pillars that hold the strongest partner relationships together: rock-solid technology, predictable commercials, a clear vision partners can invest in, and the constant work of listening. It's the foundation of trust that keeps ecosystems moving forward._________________________Learn more about Channext
Augusztusra már csak 20 centi körül lehet a Velencei-tó vízszintje Drágulhatnak a mobilok és a laptopok, nagy áremelést jelentett be az egyik legnagyobb chipgyártó Augusztus 12-én részleges napfogyatkozás lesz Magyarországon, a leglátványosabb Sopron környékén lesz Vészfrissítést kaptak az iPhone-ok A Google telepakolta a Waze-t mesterséges intelligenciával, de csak két új funkciót érdemes bekapcsolni Új kiberbiztonsági veszélyekre figyelmeztet az Eset legfrissebb jelentése Nagy erejű földrengés rázta meg Japánt Stratégiai akvizícióval erősít Magyarországon az informatikai piac meghatározó szereplője Százával lopták el a kiadatlan dalait, Ariana Grande most beperelte a hekkereket, akik meggazdagodtak belőle A további adásainkat keresd a podcast.hirstart.hu oldalunkon. Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.
Augusztusra már csak 20 centi körül lehet a Velencei-tó vízszintje Drágulhatnak a mobilok és a laptopok, nagy áremelést jelentett be az egyik legnagyobb chipgyártó Augusztus 12-én részleges napfogyatkozás lesz Magyarországon, a leglátványosabb Sopron környékén lesz Vészfrissítést kaptak az iPhone-ok A Google telepakolta a Waze-t mesterséges intelligenciával, de csak két új funkciót érdemes bekapcsolni Új kiberbiztonsági veszélyekre figyelmeztet az Eset legfrissebb jelentése Nagy erejű földrengés rázta meg Japánt Stratégiai akvizícióval erősít Magyarországon az informatikai piac meghatározó szereplője Százával lopták el a kiadatlan dalait, Ariana Grande most beperelte a hekkereket, akik meggazdagodtak belőle A további adásainkat keresd a podcast.hirstart.hu oldalunkon. Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.
This week, we are joined by Ondrej Kubovič, Security Awareness Specialist from ESET, discussing their work on "FrostyNeighbor: Fresh mischief and digital shenanigans." Ondrej walks us through ESET's latest research into FrostyNeighbor, a long-running Belarus-aligned cyberespionage group that has continued to target Ukrainian government organizations with increasingly sophisticated spearphishing campaigns. We discuss how the group uses malicious PDF lures, server-side victim validation, and an updated JavaScript-based malware chain to selectively deploy espionage tools, demonstrating its ongoing efforts to evade detection while compromising high-value targets across Eastern Europe. The research and executive brief can be found here: FrostyNeighbor: Fresh mischief and digital shenanigans
This week, we are joined by Ondrej Kubovič, Security Awareness Specialist from ESET, discussing their work on "FrostyNeighbor: Fresh mischief and digital shenanigans." Ondrej walks us through ESET's latest research into FrostyNeighbor, a long-running Belarus-aligned cyberespionage group that has continued to target Ukrainian government organizations with increasingly sophisticated spearphishing campaigns. We discuss how the group uses malicious PDF lures, server-side victim validation, and an updated JavaScript-based malware chain to selectively deploy espionage tools, demonstrating its ongoing efforts to evade detection while compromising high-value targets across Eastern Europe. The research and executive brief can be found here: FrostyNeighbor: Fresh mischief and digital shenanigans
Celé PREMIUM VIDEO nájdeš tu
Agentes de inteligencia artificial comprometidos, malware Android con GenAI, engaños más convincentes y herramientas capaces de neutralizar las defensas empresariales están marcando una nueva etapa para el cibercrimen, advierte ESET en su nuevo informe Threat Report H1 2026.
In questa puntata del Late Tech Show esploriamo come l'intelligenza artificiale e la digitalizzazione stiano trasformando settori chiave del nostro ecosistema: dalla sicurezza delle piccole e medie imprese alla gestione dei beni culturali, fino all'istruzione internazionale.Qual è lo stato della cyber-resilienza nelle PMI italiane?Insieme a Samuele Zaniboni di Eset, analizziamo i risultati di una ricerca condotta su 500 aziende italiane. Scopriamo perché, nonostante la crescente consapevolezza, il 33% delle PMI sia già stato colpito da attacchi informatici e come la cultura aziendale (coinvolgendo anche le Risorse Umane) sia la prima linea di difesa contro Ransomware e Phishing.Perché investire nella sicurezza H24 è vitale per le imprese locali?Approfondiamo il tema dei costi della sicurezza: quanto costa davvero proteggersi rispetto al fermo totale di un'azienda? Discutiamo dell'importanza di una protezione costante, 24 ore su 24, e di come l'intelligenza artificiale stia diventando un'arma fondamentale sia per gli attaccanti che per i difensori.Come si sta evolvendo il "Museo del Futuro" attraverso il digitale?Maria Emanuela Oddo, co-autrice di "Futuro Museo", ci spiega come la tecnologia stia trasformando i musei in vere e proprie "piattaforme culturali". Non si tratta solo di conservazione, ma di accessibilità territoriale e sociale, permettendo a chiunque di scoprire opere e documenti inediti (come i manoscritti di Leonardo o Michelangelo) attraverso la digitalizzazione e l'interoperabilità dei dati.In che modo l'AI sta cambiando le vacanze studio all'estero?Vanessa Rota di MLC Education racconta la nuova tendenza dei viaggi studio: gli studenti (e i genitori) non cercano più solo l'apprendimento linguistico, ma competenze tecniche legate all'intelligenza artificiale e alle discipline STEM. Vediamo come le scuole internazionali si stiano adeguando per formare i cittadini di domani.Come pianificare un percorso educativo internazionale di successo?Scopriamo l'importanza della consulenza pedagogica rispetto a quella puramente commerciale. Perché un percorso per università prestigiose come Harvard va costruito già dalle scuole medie? Vanessa ci spiega la complessità che sta dietro la mappatura delle scuole e l'importanza del rapporto umano in un mondo sempre più digitale.https://lts.businesscommunity.it Contattami per moderazioni, speech e consulenze: https://www.businesscommunity.it/gigi/contattami.php
3 - Az Egyesült Királyságban az elmúlt időszakban több olyan eset és botrány is történt, amely az OnlyFans platformot és az iskolai oktatást kapcsolta össze by Balázsék
We zijn terug aan Het Digitale Front! In drie speciale afleveringen ontvangen Art Rooijakkers, Dave Maasland en Harm Teunis experts op het gebied van cyber, geopolitiek en oorlogsvoering. Hoe oefenen de grootmachten Rusland, de Verenigde Staten en China hun invloed uit in het digitale domein? Met vandaag: journalist en voormalig China-correspondent Anouk Eigenraam over hoe China Europa steeds verder klemzet en hoe TikTok de afstandsbediening van onze samenleving is geworden. Niet voor niets waarschuwt de AIVD dat China een van de grootste dreigingen voor Nederland vormt. Want achter video's en webshops schuilt een veel grotere strijd: om data, invloed en macht. Hoe probeert China onze samenleving te sturen? En hoe voorkomt Europa dat het steeds afhankelijker wordt van China? Het Digitale Front is een coproductie van Corti Media en ESET.See omnystudio.com/listener for privacy information.
The latest on smart glasses concerns with Tony Anscombe of ESET.
We zijn terug aan Het Digitale Front! In drie speciale afleveringen ontvangen Art Rooijakkers, Dave Maasland en Harm Teunis experts op het gebied van cyber, geopolitiek en oorlogsvoering. Hoe oefenen de grootmachten Rusland, de Verenigde Staten en China hun invloed uit in het digitale domein? Met vandaag: oud-AIVD'er en directeur van Stichting Justice for Prosperity Jelle Postma over Europa's digitale afhankelijkheid van de Verenigde Staten. Niet alleen onze sociale media en AI-systemen zijn in Amerikaanse handen, ook de overheid en vitale infrastructuur, zoals ziekenhuizen, vliegvelden en havens, draaien op Amerikaanse technologie. Wat als Donald Trump besluit die afhankelijkheid als drukmiddel te gebruiken? Kan hij het digitale licht uitzetten? En hoe kwetsbaar is Europa eigenlijk?Het Digitale Front is een coproductie van Corti Media en ESET.See omnystudio.com/listener for privacy information.
Face à des cyberattaques toujours plus furtives, Benoit Grunemwald, expert cybersécurité chez ESET, décrypte les nouvelles stratégies des cybercriminels. Il explique comment l'intelligence artificielle, la supervision humaine et les nouveaux outils de protection transforment la défense numérique.
We zijn terug aan Het Digitale Front! In drie speciale afleveringen ontvangen Art Rooijakkers, Dave Maasland en Harm Teunis experts op het gebied van cyber, geopolitiek en oorlogsvoering. Hoe oefenen de grootmachten Rusland, de Verenigde Staten en China hun invloed uit in het digitale domein? Met vandaag: brigadegeneraal en hoogleraar ‘Cyber Warfare’ Paul Ducheine over de cyberstrategie van Rusland. Want hoewel Poetin misschien niet de krachtigste digitale wapens bezit, weet desinformatie uit Moskou steeds verder onze Westerse samenleving binnen te dringen en horen we steeds vaker dat Europese infrastructuur wordt platgelegd door Russische cyberaanvallen. Wat wil Poetin daarmee bereiken? En zijn we in staat terug te vechten? Het Digitale Front is een co-productie van Corti Media en ESET.See omnystudio.com/listener for privacy information.
Intel Chat with Matt Bromiley and Chris Luft.Matt and Chris break down four stories from the week in threat intel:• Cisco CUCM (CVE-2026-20230) — a web-dialer SSRF that chains to root-level RCE, exploited in the wild less than 24 hours after the PoC and full exploit chain were published.• The latest Ransomware Tool Matrix (RTM) / Ransomware Vulnerability Matrix (RVM) update, profiling three active groups — The Gentlemen, DragonForce and Warlock — and the BYOVD and legit-admin-tool tradecraft they increasingly share.• Gamaredon's upgraded toolkit against Ukraine (per ESET): new PowerShell downloaders like PteroPaste, Cloudflare tunneling and Workers for C2, and exfiltration to trusted cloud storage such as Amazon S3 and Dropbox.• Varonis Threat Labs phishing an AI email agent ("Pinchy") — why agents spot technical phishing better than humans yet hand over credentials to a convincing social request, and why you should treat them as privileged junior employees.Chapters:0:00 Intro & catching up2:25 Cisco CUCM exploited within 24h of the PoC9:57 Ransomware Tool Matrix: The Gentlemen, DragonForce & Warlock15:44 Gamaredon's upgraded TTPs against Ukraine22:18 Can AI email agents be phished?28:08 Wrap-up: Black Hat plans & the LimaCharlie suiteThe Cybersecurity Defenders Podcast — a podcast about cybersecurity and the people that keep the internet safe. New episodes drop weekly.Subscribe wherever you listen:• Spotify: https://open.spotify.com/show/6ep00zeY3S8ffZ4o0UeSps• Apple Podcasts: https://podcasts.apple.com/us/podcast/the-cybersecurity-defenders-podcast/id1649981740• YouTube: https://www.youtube.com/@limacharlieioLearn more about LimaCharlie: https://limacharlie.io#cybersecurity #infosec #threatintel #ransomware #DFIR
Ebben az epizódban egy friss magyar AI-kutatás alapján beszélgetünk vendégünkkel, Kerek Istvánnal arról, hogyan vált a mesterséges intelligencia néhány év alatt technológiai újdonságból hétköznapi munkaeszközzé.Kerek István AI üzletfejlesztési szakértő, a ChatGPT Magyarul Facebook csoport alapítója, így első kézből látja, hogyan használják az emberek a mesterséges intelligenciát a mindennapokban, a munkában, a tanulásban és az üzleti döntések előkészítésében.ChatGPT, generatív AI, deepfake, social engineering, munkahelyi adatbiztonság és mentális egészség — egy olyan témáról beszélgetünk, amely már rég nem csak az IT-sokat érinti.A kutatás egyik legerősebb állítása, hogy az AI-korszakban már nem az a fő kérdés, hogy tud-e a gép jó szöveget, képet, hangot vagy videót készíteni. Hanem az, hogy mi, emberek képesek vagyunk-e még eldönteni, mi valódi.A magyar munkavállalók jelentős része már kipróbált valamilyen AI-eszközt, sokan pedig nem hivatalos céges bevezetésen keresztül, hanem saját rutinból kezdték el használni. Ez a „shadow AI” jelenség: amikor az AI már bent van a munkahelyen, csak a szervezet még nem beszél róla. A valódi kérdés ezért nem az, hogy használjuk-e az AI-t, hanem az, hogy milyen adatokkal, milyen szabályokkal és milyen emberi ellenőrzéssel tesszük.Beszélünk arról is, hogy az AI nemcsak hatékonyabbá teszi a munkát, hanem a csalásokat is professzionálisabbá. A rossz helyesírású, gyanús adathalász e-mailek korszaka lassan véget ér: a generatív AI tökéletes magyarságú, személyre szabott, céges stílusú üzeneteket, sőt akár hang- és videóalapú megtévesztéseket is képes segíteni. Így a régi védekezés, hogy „majd észreveszem, ha valami furcsa”, egyre kevésbé elég.A deepfake és az AI-generált tartalmak miatt a bizalom technológiai kérdéssé vált. Ha egy videó, hangfelvétel vagy e-mail már nem önmagában bizonyíték, akkor új ellenőrzési kultúrára van szükség: többcsatornás visszaigazolásra, digitális aláírásokra, jóváhagyási folyamatokra és világos munkahelyi szabályokra.A riport különösen izgalmas része, hogy az AI-t nemcsak technológiai és kiberbiztonsági, hanem mentális egészségi kérdésként is kezeli. Ha folyamatosan mérlegelnünk kell, hogy amit látunk, hallunk vagy olvasunk, az valódi-e, az komoly kognitív terhelést jelent. A bizonytalanság, a gyanakvás és a kontrollvesztés érzése stresszt okozhat — a fáradt, sürgetett ember pedig könnyebben kattint, utal, ad ki adatot vagy hagy ki ellenőrzési lépéseket.Ebben az adásban nem pánikot akarunk kelteni, hanem megérteni, hogyan használhatjuk az AI-t okosan, biztonságosan és felelősen. Mert a mesterséges intelligenciát nem tiltani kell, hanem keretek közé tenni.A kutatás az ESET termékeinek kizárólagos forgalmazója, a Sicontact Kft. megbízásából készült.
Android sauve des vies au Vénézuela • Apple augmente fortement les prix de ses Mac et iPad • Meta lance des lunettes connectées bon marché • Tesla conteste un accident attribué à son Autopilot • L'Europe avance sur l'euro numérique • Les cyberarnaques profitent de la Coupe du monde • Des innovations pour la transition énergétique récompensées par les Prix EDF Pulse⭐️ Découvrez Frogans, l'innovation française qui réinvente le Web : cliquez ici===============Des smartphones Android qui sauvent des vies lors du séisme au VenezuelaLe double séisme qui a frappé le Venezuela a montré l'efficacité du système Android Earthquake Alerts de Google. Des millions d'utilisateurs Android ont reçu une alerte quelques secondes avant les secousses grâce aux accéléromètres intégrés dans les smartphones, capables de détecter les premières ondes sismiques. Une démonstration spectaculaire du potentiel des technologies mobiles au service de la sécurité civile.Apple augmente brutalement le prix de ses Mac et de ses iPadFace à la crise mondiale des semi-conducteurs, Apple revoit les tarifs de presque toute sa gamme informatique. Les Mac voient leur prix grimper de 100 à 700 euros selon les modèles, tandis que les iPad prennent jusqu'à 150 euros. Seuls les iPhone échappent, pour l'instant, à cette hausse, conséquence directe de la pénurie de mémoire vive alimentée par l'explosion de la demande liée à l'intelligence artificielle.Meta démocratise les lunettes connectéesMeta lance une nouvelle génération de lunettes connectées à environ 300 dollars, moins chère que les modèles développés avec Ray-Ban. Elles intègrent caméra, micros, haut-parleurs, traduction instantanée et assistant IA Meta, tout en conservant une approche plus accessible pour accélérer l'adoption des wearables intelligents.Tesla : l'Autopilot mis en cause… mais l'enquête nuance les accusationsUne famille américaine poursuit Tesla après un accident mortel au Texas impliquant une Model 3. Le conducteur affirme que l'Autopilot était activé, mais les données enregistrées par le constructeur indiqueraient au contraire que le conducteur avait repris la main quelques instants avant l'impact. Une nouvelle affaire qui relance le débat sur les limites des systèmes d'aide à la conduite.Waymo rappelle 4 000 robotaxisLes véhicules autonomes de Waymo ont été surpris à plusieurs reprises sur des autoroutes fermées pour travaux. L'entreprise rappelle près de 4 000 véhicules afin de corriger un défaut d'interprétation des zones de chantier. Malgré ce sixième rappel, Waymo poursuit son expansion aux États-Unis et à l'international.Le supercalculateur chinois Line Shine devient numéro un mondialLa Chine reprend la tête du classement Top500 avec Line Shine, installé à Shenzhen. Cette machine de plus de 2 000 exaflops, entièrement basée sur des processeurs chinois, dépasse désormais le supercalculateur américain El Capitan et confirme les ambitions technologiques de Pékin dans le calcul haute performance.Euro numérique : l'Europe accélèreDans le Débrief transatlantique, Bruno Guglielminetti (Mon Carnet) revient sur l'avancée du projet d'euro numérique. La future monnaie numérique de la Banque centrale européenne vise à renforcer la souveraineté européenne face aux géants américains du paiement tout en promettant un haut niveau de protection de la vie privée. Le Canada réfléchit également à un dispositif comparable, même si le sujet suscite d'importantes interrogations.Les lunettes IA de Meta : au service de l'accessibilitéINTERVIEW - Matthew Sanders, directeur de l'accessibilité et de l'impact pour les wearables IA chez Meta, explique pourquoi les lunettes intelligentes sont appelées à compléter le smartphone plutôt qu'à le remplacer. Il détaille les progrès réalisés en matière d'accessibilité grâce à l'IA, notamment pour les personnes malvoyantes, ainsi que les défis techniques liés à l'autonomie, la miniaturisation et la protection de la vie privée.Cybercriminalité : les escrocs profitent de la Coupe du mondeINTERVIEW [PARTENARIAT] - Benoît Grunemwald, expert cybersécurité chez ESET, alerte sur la multiplication des arnaques liées à la Coupe du monde de football : faux sites de billetterie, faux produits dérivés, IPTV frauduleuses et campagnes de phishing. Il explique également comment les cybercriminels développent désormais des outils capables de neutraliser les logiciels de sécurité, rendant indispensable une surveillance permanente des systèmes.EDF Pulse 2026 : six innovations pour accélérer la transition énergétiqueINTERVIEW [PARTENARIAT] - Julien Villeret, directeur de l'innovation d'EDF, présente les lauréats des Prix EDF Pulse 2026. Au programme : des vêtements rafraîchissants pour les travailleurs exposés aux fortes chaleurs, des solutions de stockage thermique pour l'industrie, le reconditionnement de batteries, l'inspection industrielle assistée par IA, un dirigeable électrique pour surveiller les infrastructures et un drone élagueur destiné à sécuriser les réseaux électriques. Autant d'innovations appelées à accompagner la transition énergétique.Hébergé par Audiomeans. Visitez audiomeans.fr/politique-de-confidentialite pour plus d'informations.
Ronald, Marco en Jelle zijn terug met AI-soevereiniteit, ransomware met eigen EDR-killers, een vals noodalarm in Brazilië, Chinese hackers in ArcGIS, je pincode afgeven aan justitie, smart-tv's als proxy en GPS-jamming vanuit de ruimte. Marco begint met Fable 5 en Mythos 5: frontier-modellen van Anthropic die onder Amerikaanse exportcontrole kwamen te liggen. Dat past in een bredere beweging van chipcontrole naar modelcontrole, met een ongemakkelijke vraag voor Europa: wat betekent AI-soevereiniteit als je modellen, chips en clouds alsnog afhankelijk zijn van Amerikaanse infrastructuur? Daarna The Gentlemen, een ransomwaregroep die zijn affiliates niet alleen encryptors geeft, maar ook eigen EDR-killers. Met BYOVD-technieken laden aanvallers kwetsbare maar nog vertrouwde drivers om securitytools uit te zetten voordat de ransomware-payload wordt uitgerold. Ook bij Marco: Brazilië kreeg een vals "Alerta Extremo" via het nationale noodwaarschuwingssysteem. De melding bevatte onder meer het woord "misantropia". De kern is niet alleen het hackverhaal, maar vooral vertrouwen: wat gebeurt er als mensen het noodalarm zelf niet meer vertrouwen? Jelle bespreekt Chinese hackers die ArcGIS misbruikten voor langdurige persistentie. Volgens ReliaQuest werd een legitieme Java Server Object Extension omgebouwd tot webshell, waarna SoftEther VPN Bridge toegang hield. Ronald bespreekt het afgeven van je pincode aan justitie. Volgens het Europees Hof voor de Rechten van de Mens is dat onder voorwaarden geen schending van je zwijgrecht. Maar een telefoon is geen kluisje met een paar documenten; het is een doorlopend logboek van je leven. Het hoofdverhaal van Jelle gaat over smart-tv's, PetFlix en de Bright SDK. Include Security onderzocht hoe apps op smart-tv's en mobiele apparaten een commerciële SDK kunnen bevatten die de internetverbinding van gebruikers inzet als residential proxy. Tot slot neemt Ronald ons mee naar GPS-jamming vanuit de ruimte. Onderzoekers zagen korte, brede storingen in GNSS-signalen boven Europa, Groenland en Canada en herleidden die tot Russische militaire satellieten. GPS is niet alleen navigatie, maar ook timing voor elektriciteitsnetten, financiële transacties, communicatie en andere kritieke infrastructuur. Bronnen: - Anthropic over Fable 5 en Mythos 5: https://www.anthropic.com/news/fable-mythos-access - White House AI executive order: https://www.whitehouse.gov/presidential-actions/2026/06/promoting-advanced-artificial-intelligence-innovation-and-security/ - ESET over The Gentlemen: https://www.welivesecurity.com/en/eset-research/killing-me-gently-inside-gentlemens-edr-killer-framework/ - Check Point over The Gentlemen-leak: https://research.checkpoint.com/2026/thus-spoke-the-gentlemen/ - Brazilië / vals noodalarm: https://agenciabrasil.ebc.com.br/meio-ambiente/noticia/2026-06/sistema-da-defesa-civil-e-suspenso-apos-invasao-e-disparo-falso - ArcGIS / Flax Typhoon: https://www.bleepingcomputer.com/news/security/chinese-hackers-abuse-geo-mapping-tool-for-year-long-persistence/ - Pincode en zwijgrecht: https://blog.iusmentis.com/2026/06/19/je-pincode-moeten-geven-aan-justitie-is-geen-schending-van-je-zwijgrecht/ - Smart-tv / Bright SDK: https://blog.includesecurity.com/2026/06/the-smart-tv-in-your-livingroom-is-a-node-in-the-aiscraping-economy/ - The Verge over PetFlix: https://www.theverge.com/column/885244/smart-tv-web-crawler-ai - Veritasium GPS-video: https://www.youtube.com/watch?v=tz23G_UXCGA - GNSS-paper: https://arxiv.org/html/2606.03673v1 DNS-blocklist uit Include Security: proxyjs.brdtnet.com proxyjs.luminatinet.com proxyjs.bright-sdk.com clientsdk.bright-sdk.com clientsdk.brdtnet.com
In dieser Folge von „WeTalkSecurity" geht es um Cybersicherheit im Gesundheitswesen – ein Sektor, der europaweit zu den Hauptzielen von Cyberangriffen zählt und gleichzeitig unter Fachkräftemangel und Budgetdruck steht. Philipp Plum spricht in Berlin mit Tony Liersch, Teamleiter IT-Infrastruktur und Support am Klinikum Garmisch-Partenkirchen, und seinem Kollegen Andreas Kretschmer über den IT-Sicherheitsalltag eines 400-Betten-Hauses: über Managed Detection and Response, Netzwerksegmentierung bei Medizingeräten, die Umsetzung von NIS2 und die Frage, wie man als kleines Team mit großer Verantwortung dauerhaft handlungsfähig bleibt.
Esta mañana en #Noticias7AM entrevistamos a David González, Investigador de seguridad informática de ESET. Tema: Falsas ofertas laborales suplantan a grandes empresas para robar datos personales en Latinoamérica#Uniradioinforma
A breach at market intelligence platform Klue allowed attackers to steal OAuth tokens linking Clue to customers' Salesforce environments, enabling quiet API-driven data extraction from firms including Huntress, Recorded Future, Tanium, and Jamf; Clue revoked tokens, removed the legacy integration credential involved, and engaged CrowdStrike as Icarus threatens extortion, echoing earlier Salesforce token-theft campaigns affecting nearly 1,000 companies. Researchers also detail AriStinger, a new botnet infecting 4,000+ end-of-life D-Link routers to scan, proxy, tunnel, execute commands, and hijack DNS, with many infections in South Korea and China. The episode covers federal cyberstalking charges against Anthony Belford for allegedly using fake accounts and AI-generated nude images, and ESET's report that the "Gentleman" ransomware crew is developing modular EDR-killing tools to disable endpoint defenses. 00:00 Top Stories Teaser 00:29 Clue OAuth Token Breach 02:32 Salesforce Token Attack Trend 04:14 AryStinger Router Botnet 05:33 AI Deepfake Cyberstalking Case 07:50 Gentleman EDR Killer Arsenal 09:37 Wrap Up And Sign Off
Can businesses still rely on cybersecurity strategies that were designed for a very different threat environment? In this episode of Tech Talks Daily, I speak with Matt Knell from ESET about why many managed service providers and businesses are being forced to rethink what effective cybersecurity looks like in 2026. As cybercriminals become faster, more sophisticated, and increasingly powered by AI, many of the approaches that once provided reassurance are struggling to keep pace. Matt shares why the idea of "good enough" security is becoming increasingly difficult to defend. While endpoint protection remains an important part of any security strategy, he explains why technology alone is no longer enough. Organizations must continually review, update, and strengthen their defenses rather than assuming that yesterday's protections will be sufficient tomorrow. Our conversation explores the lasting impact of ransomware and the lessons businesses continue to learn from high-profile incidents. From major retailers to global manufacturers, attacks are creating operational disruption, financial losses, and reputational damage on a scale that few organizations would have imagined a decade ago. We also discuss one of the industry's most persistent challenges: the cybersecurity skills gap. Finding experienced security professionals remains difficult, while retaining talent has become equally challenging. Matt explains how managed detection and response services are helping MSPs extend their capabilities without having to build and maintain large security operations teams. AI naturally plays a major role in the discussion. While cybersecurity vendors use AI to improve threat detection and response, attackers are also leveraging the technology to accelerate and sophisticate phishing campaigns, social engineering, and other forms of cybercrime. Matt explains why businesses must remain realistic about both opportunities and risks. Another theme throughout the episode is the growing expectation that cybersecurity should be treated as a business issue rather than purely an IT concern. Regulations, cyber insurance requirements, supply chain scrutiny, and customer expectations are all increasing pressure on organizations to demonstrate stronger security practices and greater resilience. We also discuss ESET PRIVATE and why more organizations are seeking security services tailored to their specific operational needs. Rather than relying on a standard package, many businesses are looking for solutions that align with their industry requirements, compliance obligations, risk profile, and long-term objectives. Finally, Matt reflects on the conversations emerging from ESET's recent partner conference and shares his perspective on the topics shaping cybersecurity priorities for the coming year. AI, resilience, compliance, and business education continue to dominate discussions as organizations look for practical ways to strengthen their defenses. If you're an MSP, IT leader, business owner, or anyone responsible for protecting digital operations, this episode offers a timely look at the challenges facing organizations today and the steps many are taking to prepare for what comes next. Is your organization still relying on security strategies designed for yesterday's threats, or have you adapted to today's cyber risks?
Originally recorded: Friday May 22, 2026In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the LimaCharlie community.GitHub has confirmed that roughly 3,800 internal repositories were accessed in a supply chain compromise tied to the hacking group TeamPCP.China-aligned threat actor Webworm has shifted its targeting focus from Asia to Europe, according to new research published by ESET.Researchers uncovered a previously undocumented Microsoft 365 account takeover panel that integrates directly with Evilginx Pro infrastructure to streamline token theft and post-compromise operations.European and North American law enforcement agencies announced the dismantling of “First VPN,” a VPN service allegedly built to support cybercriminal activity including ransomware operations, data theft, scanning, and denial-of-service attacks.Support our show by sharing your favorite episodes with a friend, subscribe, give us a rating or leave a comment on your podcast platform.This podcast is brought to you by LimaCharlie, maker of the SecOps Cloud Platform, infrastructure for SecOps where everything is built API first. Scale with confidence as your business grows. Start today for free at limacharlie.io.
Ronald, Marco en Jelle zijn terug met een aflevering over criminelen, Cloudflare, consultants en piepers. Dave Maasland verkoopt ESET Nederland aan het Slowaakse moederbedrijf ESET, Ronald duikt in het Follow the Money-interview met TIB-voorzitter Annemieke Zwanenveld over de nieuwe Wiv, toetsing, CTIVD/TIB-samenvoeging, witte jassen en Palantir. Daarna Jelle's human-interest ransomwareverhaal: The Gentlemen RaaS werd zelf gehackt via de hostinglaag achter hun Rocket.Chat, waardoor Check Point kon meekijken in interne chats, payouts, AI-assisted coding en het kantoortje achter ransomware. Marco sluit af met Google Threat Intelligence over Chinese phishing-as-a-service: betere lokalisatie, RCS/iMessage en AI als contextversneller. Daarna het hoofdverhaal: Cloudflare heeft via Anthropic's Project Glasswing Mythos op meer dan 50 repositories losgelaten. Marco legt uit waarom dat niet neerkomt op "druk op knop, vind zero-days", maar op exploit-chain construction, proof generation, signal-to-noise en vooral: een hele vulnerability-research-harness met recon, hunt, validate, gapfill, dedupe, trace en report. Geen magische silver bullet, wel een duidelijke versnelling voor wie de workflow eromheen bouwt. Jelle pakt vervolgens McKinsey Lilli en BCG X erbij. CodeWall liet zien hoe interne AI-platforms zelf attack surface worden: publieke API-documentatie, endpoints zonder authenticatie, SQL-injectie, IDOR, miljoenen chats en files, system prompts, workspaces, modelconfiguraties en complete datawarehouses. Het echte verhaal: organisaties stoppen hun kennislaag, documenten, prompts en besluitvorming steeds meer in platforms. Wie daarin zit, zit bijna in het geheugen van de organisatie. Ronald en Marco sluiten af met het Mossad-pieperverhaal. Naar aanleiding van een nieuw Hebreeuws boek en een interview in The Jerusalem Post lopen ze door hoe de Hezbollah-pagers en walkie-talkies als supply-chain-operatie zouden zijn opgebouwd: techniek, infiltratie, Gold Apollo, BAC Consulting, Iraanse argwaan en de spanning tussen "ongelooflijk knap" en "hier zijn mensen door gestorven". *Bronnen* - Tweakers, "Slowaakse ESET koopt Nederlandse ESET": https://tweakers.net/nieuws/248036/slowaakse-eset-koopt-nederlandse-eset.html - ESET press release: https://www.eset.com/us/about/newsroom/company/eset-market-expansion-europe-asia/ - Follow the Money, "Geheime diensten gebruiken onafhankelijke experts om publiek debat te sturen": https://www.ftm.nl/artikelen/geheime-diensten-zetten-onafhankelijke-experts-in - Check Point Research, "When the Ransomware Gang Gets Hacked": https://blog.checkpoint.com/research/when-the-ransomware-gang-gets-hacked-what-the-gentlemen-leak-reveals-about-modern-ransomware-risk/ - Cloudflare Blog, Grant Bourzikas, "Project Glasswing: what Mythos showed us": https://blog.cloudflare.com/cyber-frontier-models/ - Anthropic, Project Glasswing: https://www.anthropic.com/glasswing - CodeWall, "How We Hacked McKinsey's AI Platform": https://codewall.ai/blog/how-we-hacked-mckinseys-ai-platform - CodeWall, "How We Hacked BCG's Data Warehouse": https://codewall.ai/blog/how-we-hacked-bcgs-data-warehouse-3-17-trillion-rows-zero-authentication - The Jerusalem Post, "Inside Israel's secret operation to turn Hezbollah's beepers into bombs": https://www.jpost.com/israel-news/defense-news/article-896890
Depuis ses 12 ans, Andie Ella filme des vidéos dans sa chambre.Passionnée de maquillage, elle apprend seule sur YouTube, elle rêve de devenir maquilleuse.Elle part à 15 ans de chez elle et commence très jeune à construire sa vie à sa manière.Pendant des années, elle partage son quotidien en ligne jusqu'à créer une communauté ultra fidèle qui aujourd'hui réunit 1 million de personnes.Mais dans ses vidéos, un détail revient sans cesse : son matcha.À force de voir ses abonnés lui demander où trouver un bon matcha, elle décide de créer sa propre marque. son objectif, changer l'image du matcha en France.Le lancement est fulgurant. Ruptures de stock, croissance rapide, équipe qui s'agrandit… En quelques années, Milia Matcha devient bien plus qu'une marque d'influenceuse mais un empire.Dans cet épisode, tu découvriras :Ses débuts sur YouTube à seulement 12 ansPourquoi elle a quitté l'école très jeuneLes coulisses du lancement de Milia MatchaSon hypercroissance en seulement quelques annéesEt comment elle construit aujourd'hui une marque qui la dépasse complètement////////////////////////////////////////////////////////////////////////////////////
Agentic AI was the theme that pulled away from the pack at RSAC Conference 2026. Tony Anscombe of ESET makes the case that once AI shifts from being directed by humans to operating with its own objectives and logic, the security surface changes with it, and organizations are being forced to rethink what they protect and how. At the show, ESET announced two products that meet that moment head on. The ESET AI Skills Checker is a free-to-use tool coming to market. ESET AI Protection looks inside AI sessions on the endpoint, flagging sensitive data leakage, malicious links returned by AI systems, and suspicious behavior, and surfacing it all inside normal cybersecurity operations for investigation, blocking, or detection. Tony closes with a reminder worth keeping. His first RSA was in 1998, and the technology he worked on then (sandboxing, dynamic code, remote windowing, encryption, authentication) mirrors a lot of what walks the RSAC Conference floor today. The packaging evolves, the core principles do not. Build forward, but do not lose sight of what the past already proved. This is a Brand Highlight. A Brand Highlight is a ~5 minute introductory conversation designed to put a spotlight on the guest and their company. Learn more: https://www.studioc60.com/creation#highlight GUEST Tony Anscombe, Chief Security Evangelist, ESET LinkedIn: https://www.linkedin.com/in/tonyanscombe/ RESOURCES Learn more about ESET: https://www.eset.com ESET AI Skills Checker and ESET AI Protection: https://www.eset.com Are you interested in telling your story? ▶︎ Full Length Brand Story: https://www.studioc60.com/content-creation#full ▶︎ Brand Spotlight Story: https://www.studioc60.com/content-creation#spotlight ▶︎ Brand Highlight Story: https://www.studioc60.com/content-creation#highlight KEYWORDS Tony Anscombe, ESET, Sean Martin, brand story, brand marketing, marketing podcast, brand highlight, agentic AI, AI security, RSAC Conference 2026, threat intelligence, MDR, EDR, endpoint security, AI Skills Checker, AI Protection, cybersecurity community, multifactor authentication, cybersecurity evolution Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.
Microsoft confirms active exploitation of two Defender flaws. Europol dismantles a VPN service tied to ransomware gangs. A nine-year-old Linux kernel bug exposes SSH keys and password hashes. Cisco patches a critical Secure Workload vulnerability, while Drupal fixes a highly critical SQL injection flaw. Android malware quietly signs victims up for premium SMS scams. Webworm upgrades its espionage toolkit with Discord and Microsoft Graph backdoors. Plus, China and Russia deepen cooperation on AI, cybersecurity, and satellite systems. Our guest is Jake Moore, Global Cybersecurity Advisor for ESET, sharing a glimpse into his Infosecurity Europe keynote "The Deepfake Interview." Greg doesn't even work here anymore… Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Today, Maria Varmazis speaks with Jake Moore, Keynote speaker for the upcoming Infosecurity Europe conference and Global Cybersecurity Advisor for ESET, getting a glimpse into his session "The Deepfake Interview: Breaking In From the Inside." This interview is part of our partnership with Infosecurity Europe. Selected Reading Microsoft Defender vulnerabilities exploited in the wild (Help Net Security) Europol Seizes First VPN Used by Ransomware Gangs, Arrests Administrator (Hackread) Nine-Year-Old Linux Kernel Flaw Leaks SSH Keys and Password Hashes (Infosecurity Magazine) Cisco Patches Critical Vulnerability in Secure Workload (SecurityWeek) Android Malware Spotted Subscribing Victims to Paid Services Without Consent (Hackread) Drupal Patches Highly Critical Vulnerability Exposing Websites to Hacking (SecurityWeek) Webworm: New burrowing techniques (We Live Security) Xi and Putin pledge closer cooperation on AI, cyberspace and satellite systems (The Record) Zombie user account let hackers control the city's water (The Register) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc. Learn more about your ad choices. Visit megaphone.fm/adchoices
Zabudnite na osamelých hackerov v tmavých pivniciach z akčných filmov. Dnešný kybernetický zločin funguje ako vysoko organizovaná IT korporácia s jasnou hierarchiou a prepracovaným marketingom. Ich najčastejším a najobľúbenejším terčom sa pritom prekvapivo stali malé a stredné podniky na Slovensku.Útočníci si z napádania menších firiem vytvorili lukratívny ekosystém. Prečo sú práve slovenské malé podniky dokonalým cieľom? Majú dostatok cenných dát aj peňazí, no chýbajú im špecializované oddelenia kyberbezpečnosti. Hackeri už nerosielajú zle preložené spamy, ale dokonale vizuálne napodobňujú reálne inštitúcie, ako je napríklad Západoslovenská energetika (ZSE). Stačí jediné kliknutie na zdanlivo nevinné tlačidlo v maily s faktúrou a útočníci získajú prístup do firemnej siete, ktorý môžu na čiernom trhu predať ransomvérovým gangom za tisíce eur.O tom, ako táto digitálna mafia funguje a kedy presne treba byť v práci najviac v strehu, sa v podcaste SHARE rozprával Maroš Žofčin so špecialistom na digitálnu bezpečnosť Ondrejom Kubovičom a výskumníkom malvéru Jakubom Kaločom zo spoločnosti Eset.Podcast vznikol v spolupráci so spoločnosťou Eset.Pripravte sa na budúcnosť s knihou od redaktorov Živé.sk „Umelá inteligencia: Pripravte sa na budúcnosť“. Teraz ju máme aj v elektronickej verzii. Nájdete ju na obchod.aktuality.sk.TIP: https://zive.aktuality.sk/clanok/0RfdZVW/nahliadnite-do-buducnosti-vydavame-knihu-o-umelej-inteligencii/V podcaste sa dozviete aj o týchto témach:Prečo sú malé a stredné slovenské podniky zlatou baňou pre kyberzločincov.Prečo útočné e-maily prichádzajú najčastejšie presne medzi 9:00 a 10:00 alebo po druhej poobede.Ako rozoznať podvrhnutú faktúru, ktorá vizuálne do detailu kopíruje reálne slovenské firmy.Ako funguje biznis model, kde si „operátori“ prenajímajú škodlivý kód takzvaným „partnerom“.Odstrašujúci prípad firmy CloudEye, ktorá predávala malvér pod zámienkou ochranného programu.Prečo hackerom v skutočnosti nejde o zaplatenie falošného nedoplatku z faktúry, ale o prihlasovacie údaje.Podcast SHARE pripravuje magazín Živé.sk.
Aujourd'hui, je te recommande un podcast… dans lequel j'ai été interviewée !Marine m'a invitée dans Work in Process pour parler d'un sujet qu'on adore toutes les deux :les petites offres (ou “produits d'appel”, ou “offres pied dans la porte”).L'épisode s'intitule « Comment créer des produits d'appel et des petites offres irrésistibles ».On y parle :– de quand et pourquoi créer ce type d'offres– de comment les promouvoir efficacement– et de pourquoi elles sont souvent sous-estiméesEt si tu veux prolonger ta réflexion, je t'ai préparé une petite sélection de Minutes Marines :– MM#99 : c'est quoi une offre de service ?– MM#102 : les offres pied dans la porte– MM#188 : les différents types d'offresEt toi, t'as déjà testé une offre pied dans la porte ?Tu sais ce que tu veux vendre, et à qui ?(Pour me répondre, envoie-moi un mp sur Linkedin
Send us Fan MailWhat happens when cybersecurity meets fatherhood, leadership, and real-life decision making?
The dominant structural shift discussed in the episode is the movement from tools-based differentiation to a market defined by proof and liability. This shift is driven by the rising demand for continuous, auditable control over data location, access, and change—requirements increasingly codified by policy mandates, insurance underwriting, and regional AI governance. As illustrated by France's shift away from Windows to Linux across government ministries, enforced through formal governmental policy, the conversation is moving beyond technology preferences to mandated operational boundaries and verifiable compliance. The episode cites findings from ESET's 2026 SMB Cyber Readiness Index, reporting that 86% of US SMBs and 78% of Canadian SMBs carry cyber insurance, with over half of US-insured SMBs required to implement explicit security controls by insurers. Underwriters increasingly demand evidence of controls like MFA, immutable backups, and EDR—not just attestations—at renewal, underwriting, and post-incident. Public sector mandates, such as France's comprehensive push for sovereignty encompassing OS, collaboration, cloud, and AI platforms, are producing enforceable requirements that cascade to commercial contracts and the MSP channel. Supporting developments include Gartner's forecast that by 2027, 35% of countries will be locked into region-specific AI platforms. This is reinforced by channel research from Channel Insider and a survey of 333 MSPs by AvePoint and Omnia, both pointing to governance—not AI tooling—as the leading blocker for MSPs adopting new technologies. Microsoft's move toward metered AI billing and the proliferation of shadow data (with more than 80% of sensitive data potentially sitting outside formal controls, according to Palo Alto Networks research) further highlight how operational complexity and fragmented governance elevate risk for service providers. For MSPs and IT leaders, these trends increase contractual and operational exposure. Failure to recognize that the market is purchasing assurance rather than tool support will leave providers absorbing liabilities related to insurance control failures and unmetered operational costs, often under fixed-fee models that do not account for new governance demands. Providers are advised to immediately review contract language for obligations tied to security controls, reconsider pricing and scope in governance delivery, and prepare for insurer-driven requirements such as third-party access to telemetry or continuous control attestations. The takeaway is that defensible, auditable evidence—not stack management—will define margins, accountability, and long-term client relationships. 00:00 Sovereignty Squeeze 04:22 Spawl Blindspot 07:02 Proof Pays 09:35 Why Do We Care? Supported by: ScalePad CometBackup
El programa 2861 de Radiogeek, les habló de varios temas importantes. Un rumor afirma que iOS 27 dejará a cuatro iPhone sin compatibilidad; Despídete de los deepfakes de famosos en YouTube; Google Fotos acaba de lanzar un filtro de belleza para 1.500 millones de personas; Trump elogia a Tim Cook; Trump insinúa un posible acuerdo entre el Pentágono y Anthropic a medida que disminuyen las tensiones; por ultimo hablo de la portada de Economista y del ESET security days 2026 en Argentina. Toda esta información la pueden encontrar desde nuestra web www.infosertec.com.ar o bien desde el canal de Telegram/Whastapp, o Instagram. Esperamos sus comentarios.
So you want to be a CISO? Do you know what that role entails? It depends on a number of factors, including industry, country location, technical vs. business, and more. Each position is more different than you think. Joanna Chen, Chief Information Security Officer at Dashlane, joins Business Security Weekly to discuss why not all CISO gigs are created equal. As a "technical" CISO in a foreign country, Joanna realized that not all of her peers came from a technical background, like herself. It's a broad world and the CISO role varies a lot. Joanna will discuss how to understand the various CISO roles and discuss the skills that are makers and breakers. Managing Cyber Risk as Financially Motivated Attacks Grow The ransomware and eCrime landscape continue to evolve at a rapid pace. ESET's global research team has been closely following ransomware gang disruptions and their use of EDR Killers to disable cybersecurity tools. In this interview, Tony Anscombe will take a look into recent research, and explore how the industry and businesses are responding to combat financial risk and mitigate threats. This segment is sponsored by ESET. Visit https://securityweekly.com/esetrsac to learn more about them! Attack Surface Just Got a Copilot AI adoption is accelerating faster than most organizations can secure it — and the consequences are showing up in email inboxes, collaboration platforms, and the shadow tools employees use every day. According to Mimecast's State of Human Risk 2026, 80% of organizations are concerned about sensitive data exposure through generative AI tools, yet 60% still lack strategies to address AI-driven threats. The result is a growing gap between the security investments organizations are making and the protection they're actually getting. In this conversation, Rob Juncker will explore why human behavior has become the defining variable in enterprise cybersecurity, how shadow AI is creating new data exposure and insider risk vectors, and what it takes for security architectures to adapt in real time — without slowing down the business. This segment is sponsored by Mimecast. Visit https://securityweekly.com/mimecastrsac to learn more about them! Visit https://www.securityweekly.com/bsw for all the latest episodes! Show Notes: https://securityweekly.com/bsw-443
So you want to be a CISO? Do you know what that role entails? It depends on a number of factors, including industry, country location, technical vs. business, and more. Each position is more different than you think. Joanna Chen, Chief Information Security Officer at Dashlane, joins Business Security Weekly to discuss why not all CISO gigs are created equal. As a "technical" CISO in a foreign country, Joanna realized that not all of her peers came from a technical background, like herself. It's a broad world and the CISO role varies a lot. Joanna will discuss how to understand the various CISO roles and discuss the skills that are makers and breakers. Managing Cyber Risk as Financially Motivated Attacks Grow The ransomware and eCrime landscape continue to evolve at a rapid pace. ESET's global research team has been closely following ransomware gang disruptions and their use of EDR Killers to disable cybersecurity tools. In this interview, Tony Anscombe will take a look into recent research, and explore how the industry and businesses are responding to combat financial risk and mitigate threats. This segment is sponsored by ESET. Visit https://securityweekly.com/esetrsac to learn more about them! Attack Surface Just Got a Copilot AI adoption is accelerating faster than most organizations can secure it — and the consequences are showing up in email inboxes, collaboration platforms, and the shadow tools employees use every day. According to Mimecast's State of Human Risk 2026, 80% of organizations are concerned about sensitive data exposure through generative AI tools, yet 60% still lack strategies to address AI-driven threats. The result is a growing gap between the security investments organizations are making and the protection they're actually getting. In this conversation, Rob Juncker will explore why human behavior has become the defining variable in enterprise cybersecurity, how shadow AI is creating new data exposure and insider risk vectors, and what it takes for security architectures to adapt in real time — without slowing down the business. This segment is sponsored by Mimecast. Visit https://securityweekly.com/mimecastrsac to learn more about them! Show Notes: https://securityweekly.com/bsw-443
So you want to be a CISO? Do you know what that role entails? It depends on a number of factors, including industry, country location, technical vs. business, and more. Each position is more different than you think. Joanna Chen, Chief Information Security Officer at Dashlane, joins Business Security Weekly to discuss why not all CISO gigs are created equal. As a "technical" CISO in a foreign country, Joanna realized that not all of her peers came from a technical background, like herself. It's a broad world and the CISO role varies a lot. Joanna will discuss how to understand the various CISO roles and discuss the skills that are makers and breakers. Managing Cyber Risk as Financially Motivated Attacks Grow The ransomware and eCrime landscape continue to evolve at a rapid pace. ESET's global research team has been closely following ransomware gang disruptions and their use of EDR Killers to disable cybersecurity tools. In this interview, Tony Anscombe will take a look into recent research, and explore how the industry and businesses are responding to combat financial risk and mitigate threats. This segment is sponsored by ESET. Visit https://securityweekly.com/esetrsac to learn more about them! Attack Surface Just Got a Copilot AI adoption is accelerating faster than most organizations can secure it — and the consequences are showing up in email inboxes, collaboration platforms, and the shadow tools employees use every day. According to Mimecast's State of Human Risk 2026, 80% of organizations are concerned about sensitive data exposure through generative AI tools, yet 60% still lack strategies to address AI-driven threats. The result is a growing gap between the security investments organizations are making and the protection they're actually getting. In this conversation, Rob Juncker will explore why human behavior has become the defining variable in enterprise cybersecurity, how shadow AI is creating new data exposure and insider risk vectors, and what it takes for security architectures to adapt in real time — without slowing down the business. This segment is sponsored by Mimecast. Visit https://securityweekly.com/mimecastrsac to learn more about them! Visit https://www.securityweekly.com/bsw for all the latest episodes! Show Notes: https://securityweekly.com/bsw-443
So you want to be a CISO? Do you know what that role entails? It depends on a number of factors, including industry, country location, technical vs. business, and more. Each position is more different than you think. Joanna Chen, Chief Information Security Officer at Dashlane, joins Business Security Weekly to discuss why not all CISO gigs are created equal. As a "technical" CISO in a foreign country, Joanna realized that not all of her peers came from a technical background, like herself. It's a broad world and the CISO role varies a lot. Joanna will discuss how to understand the various CISO roles and discuss the skills that are makers and breakers. Managing Cyber Risk as Financially Motivated Attacks Grow The ransomware and eCrime landscape continue to evolve at a rapid pace. ESET's global research team has been closely following ransomware gang disruptions and their use of EDR Killers to disable cybersecurity tools. In this interview, Tony Anscombe will take a look into recent research, and explore how the industry and businesses are responding to combat financial risk and mitigate threats. This segment is sponsored by ESET. Visit https://securityweekly.com/esetrsac to learn more about them! Attack Surface Just Got a Copilot AI adoption is accelerating faster than most organizations can secure it — and the consequences are showing up in email inboxes, collaboration platforms, and the shadow tools employees use every day. According to Mimecast's State of Human Risk 2026, 80% of organizations are concerned about sensitive data exposure through generative AI tools, yet 60% still lack strategies to address AI-driven threats. The result is a growing gap between the security investments organizations are making and the protection they're actually getting. In this conversation, Rob Juncker will explore why human behavior has become the defining variable in enterprise cybersecurity, how shadow AI is creating new data exposure and insider risk vectors, and what it takes for security architectures to adapt in real time — without slowing down the business. This segment is sponsored by Mimecast. Visit https://securityweekly.com/mimecastrsac to learn more about them! Show Notes: https://securityweekly.com/bsw-443
On the RSAC Conference show floor, Tony Anscombe shared how ESET has expanded its threat intelligence offering with ECR reports -- designed to give commercial organizations both machine-readable feeds and human-readable analysis. The reason: threat actors are increasingly hard to attribute, they share tools, run coordinated campaigns, and reinvest profits into more sophisticated operations. Having someone do the research and surface actionable intelligence is no longer a luxury. Anscombe pointed to a telling campaign pattern from last year: threat actors refined attack methods against UK retailers, then rapidly adapted those same techniques against US retailers. The implication is clear -- your business may be unique in its infrastructure, but it is not unique in its sector. Understanding how your sector is being targeted is the foundation of a prevention-first posture. Automation came up as equally non-negotiable. If it takes three days to collect all the information needed to make a determination about an incident, the post-attack phase has already begun. ESET Inspect is designed to flip that equation: when an analyst opens an incident, the forensic analysis is done, the evidence is visualized, and the determination can be made on facts rather than gathered through investigation. Anscombe was careful to draw a line between automation as speed and automation as replacement. ESET's position is that AI should operate alongside human expertise -- trust and verify applies to AI-assisted analysis just as it does to any intelligence feed. Oversight remains essential, even as the tooling gets faster. A preview of upcoming survey data offered one of the more striking moments in the conversation. Roughly 35% of SMBs using MDR are sourcing that service directly from their cyber insurer. Anscombe flagged the monoculture risk: when a large share of businesses in the same sector run identical security stacks, a single point of failure becomes a sector-wide vulnerability. His advice after 30 years in the industry -- different organizations should deliberately choose different platforms to maintain diversity. This is a Brand Spotlight. A Brand Spotlight is a ~15 minute conversation designed to explore the guest, their company, and what makes their approach unique. Learn more: https://www.studioc60.com/creation#spotlight GUEST Tony Anscombe, Chief Security Evangelist, ESET LinkedIn: https://www.linkedin.com/in/tonyanscombe/ RESOURCES ESET: https://www.eset.com ESET Threat Intelligence: https://www.eset.com/int/business/services/threat-intelligence/ Are you interested in telling your story? ▶︎ Full Length Brand Story: https://www.studioc60.com/content-creation#full ▶︎ Brand Spotlight Story: https://www.studioc60.com/content-creation#spotlight ▶︎ Brand Highlight Story: https://www.studioc60.com/content-creation#highlight KEYWORDS Tony Anscombe, ESET, Sean Martin, Marco Ciappelli, brand spotlight, brand marketing, marketing podcast, threat intelligence, cyber resilience, MDR, EDR, XDR, managed detection and response, SMB security, cybersecurity automation, RSAC Conference 2026, prevention-first security, cyber insurance, monoculture risk, ESET Inspect, APT research Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.
Les cybercriminels passent à la vitesse supérieure avec des attaques toujours plus crédibles et automatisées. Entre faille critique sur iOS et arnaques dopées à l'IA, les risques n'ont jamais été aussi élevés.Interview : Benoît Grünenwald, expert cybersécurité chez ESETEn partenariat avec ESETPunchlinesLes deepfakes deviennent de plus en plus crédibles.Les cyberattaques sont désormais industrialisées.Les données personnelles alimentent les arnaques ciblées.Mettre à jour ses appareils est indispensable.Parlons tout d'abord ce cette faille iOS particulièrement inquiétante : de quoi s'agit-il ?Cette alerte va au-delà d'une simple faille. On parle d'un kit d'exploit, c'est-à-dire un ensemble d'outils permettant d'utiliser une vulnérabilité pour prendre le contrôle d'un appareil. Dans ce cas précis, il suffit de visiter un site piégé avec un iPhone non à jour pour être infecté. Le scénario est simple : je reçois un SMS avec un lien, je clique, j'arrive sur un site compromis, et l'exploit s'exécute automatiquement. À partir de là, l'attaquant peut prendre le contrôle total de mon téléphone et accéder à mes données personnelles comme les contacts, les photos ou ma position.Nouveau sur le marché : les arnaques de livraison à base de deepfakesEn effet, on observe une nouvelle génération d'arnaques utilisant des images générées par IA. Par exemple, je reçois un message d'un prétendu livreur avec une photo d'un colis à mon nom, parfois même avec mon adresse. Ce qui change, c'est la personnalisation et l'industrialisation. Les cybercriminels ne se contentent plus de messages génériques : ils utilisent des bases de données et des outils automatisés pour générer des messages et des images sur mesure à grande échelle. Même si certaines images peuvent sembler imparfaites, elles deviennent de plus en plus crédibles. Et surtout, dans un contexte d'urgence ou de distraction, elles peuvent facilement tromper.Pourquoi le phishing explose-t-il autant aujourd'hui ?Les fuites de données jouent un rôle clé. Elles fournissent aux cybercriminels une énorme quantité d'informations personnelles qu'ils exploitent pour rendre leurs attaques plus convaincantes. On observe aussi une diversification des scénarios : colis, sécurité sociale, offres promotionnelles… Par exemple, des fausses offres de cartes de réduction très attractives peuvent inciter à cliquer rapidement sans vérifier. Les attaques sont de mieux en mieux construites, avec des noms de domaine crédibles et des messages personnalisés. Si on prend le temps d'analyser, on peut détecter des incohérences, mais dans la précipitation, le risque d'erreur est réel.Quels sont les réflexes essentiels pour se protéger ?Le premier réflexe, c'est la vigilance face aux messages non sollicités, quel que soit le canal : SMS, email ou messagerie. Le second, fondamental, c'est de maintenir tous ses appareils à jour. Dès qu'une mise à jour est disponible, il faut l'installer. C'est une mesure simple mais essentielle pour se protéger contre les failles connues.Hébergé par Audiomeans. Visitez audiomeans.fr/politique-de-confidentialite pour plus d'informations.
Décision de justice historique contre les géants des réseaux sociaux. OpenAI se prépare à la Bourse. Anthropic invente l'agent IA télécommandé. Google crée un "compresseur" pour IA afin d'économiser la mémoire informatique. Sony abandonne son projet de voiture. Nouvelle cyberarnaque au deepfake. Une bibliothèque mondiale du logiciel
RSAC: Retiring "APT," FCC's US-Made Router Ban, Zoom Call Scraping, Iran-Targeting Wiper, and Cyber Terrorism Insurance From RSAC 2026, host David Shipley highlights ESET researcher Robert Lipowsky's argument to retire the overused "advanced persistent threat" label and instead describe actors by motivation and activity, noting blurred lines between nation-state and criminal tooling. He also reports RSAC vendor trends (zero trust fading, "agentic AI" everywhere) and standout booth themes. In Washington, the FCC bans authorization of any new Wi‑Fi router models not made in the United States, citing supply-chain risk and attacks like Volt Flax and Salt Typhoon, impacting an industry largely manufacturing abroad unless exemptions are granted with plans to reshore. The episode details Webinar TV allegedly joining public Zoom links to record calls and publish AI-generated podcast recaps, and a Kubernetes-targeting campaign linked to the Trivy supply-chain attack that deploys an Iran-checking wiper. Finally, Treasury seeks comments on expanding the terrorism risk insurance backstop (TRIP) to cover cyber losses. Cybersecurity Today would like to thank Meter for their support in bringing you this podcast. Meter delivers a complete networking stack, wired, wireless and cellular in one integrated solution that's built for performance and scale. You can find them at Meter.com/cst 00:00 Sponsor Meter Intro 00:18 Headlines Preview 00:58 Retiring The APT Label 02:51 RSAC Floor Trends 05:08 FCC Router Ban 06:43 Zoom Calls Turned Podcasts 09:29 Iran Targeting Wiper 10:57 Cyber Terrorism Insurance Debate 13:15 Wrap Up And Thanks 13:44 Sponsor Meter Outro
Tony Anscombe has attended RSA Conference since 1998 -- back when it was held at the Fairmont Hotel. That long view informs everything about how ESET approaches threat intelligence. It is not about volume. It is about accuracy, speed, and putting the right signal in front of the right team at the right moment. The ESET eCrime Ecosystem Report comes in two forms: a business-facing summary outlining current risks for leadership, and a long-form technical report for analysts -- complete with IOCs, coding examples, and structured intelligence feeds covering ransomware, crypto scams, malicious email attachments, and infostealer data. These feeds are built to plug directly into SOC workflows and firewall rules, not to create more work for already stretched teams. Tony Anscombe is direct about the quality problem in threat intelligence. Open-source feeds sound appealing -- until you factor in the analyst hours required to clean out the noise. By then, the intelligence is stale. Attacks circle the globe in hours. Near-real-time, verified intelligence is not a premium -- it is the baseline requirement. The threat detection conversation has also moved well past malware. Anscombe walks through how modern attackers often skip the payload entirely -- credential theft gets them in, then slow lateral movement and data exfiltration follow, with ransomware as the final act rather than the first signal. ESET's platform focuses on behavioral anomaly detection across the full environment, with on-site, cloud, and managed deployment options for organizations that cannot or will not go all-in on cloud architecture. At RSAC Conference 2026, ESET will be at booth 5253 in Moscone North. Anscombe has two sessions on the Wednesday agenda: one on supply chain blind spots -- urging security teams to engage directly with the business side to map third-party risk fully -- and a community rant session tackling four things that need to change in cybersecurity, including the cryptocurrency regulation debate. On AI, his message is measured: the real conversation at the show is not about using AI -- it is about securing it. This is a Brand Spotlight. A Brand Spotlight is a ~15 minute conversation designed to explore the guest, their company, and what makes their approach unique. Learn more: https://www.studioc60.com/creation#spotlight GUEST Tony Anscombe, Chief Security Evangelist, ESET LinkedIn: https://www.linkedin.com/in/tonyanscombe/ RESOURCES ESET website: https://www.eset.com ESET threat research blog (WeLiveSecurity): https://www.welivesecurity.com ESET at RSAC Conference 2026 -- Booth 5253, Moscone North Are you interested in telling your story? ▶︎ Full Length Brand Story: https://www.studioc60.com/content-creation#full ▶︎ Brand Spotlight Story: https://www.studioc60.com/content-creation#spotlight ▶︎ Brand Highlight Story: https://www.studioc60.com/content-creation#highlight KEYWORDS Tony Anscombe, ESET, Sean Martin, RSAC Conference 2026, eCrime, threat intelligence, eCrime Ecosystem Report, cybersecurity, endpoint protection, MDR, threat detection, supply chain security, AI security, ransomware, infostealer, brand spotlight, brand marketing, marketing podcast, brand story Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.
(Presented by TLPBLACK: High-fidelity threat intelligence and research tools for modern security teams. From curated Passive DNS and real-time C2 monitoring to actionable IOC feeds and daily malware samples, we help defenders detect, hunt, and disrupt threats faster, with seamless integration into SIEM and SOAR workflows.) Three Buddy Problem - Episode 89: We discuss Iran hacktivist group 'Handala' wiper attacks against US medical device maker Stryker, Microsoft Intune MDM tool abuse, and whether Iran's cyber retaliation is as scary as the headlines suggest. Plus, ESET's discovery that Russia's APT28 original implant developers are back after years of silence, Dutch intelligence warnings on Russian campaigns targeting Signal and WhatsApp accounts, Apple finally patching Coruna exploit kit vulnerabilities for older iPhones, and Google sharing Coruna samples that raise new questions about the exploit kit's proliferation chain. Cast: Juan Andres Guerrero-Saade, Ryan Naraine and Costin Raiu.
The MSP market is undergoing a critical shift toward risk management as the central value proposition, with operational accountability now defined by the ability to produce defensible documentation and deliver rapid incident response. According to Dave Sobel, MSPs are no longer primarily offering stack management, but are increasingly brokering risk through cyber warranties, insurance underwriting, incident retainers, and AI governance frameworks. Those unable to support their claims with evidence and formal processes risk becoming mere facilitators for third-party terms and losing control over their margins. Recent developments reinforce this shift. A Splunk report finds that nearly all CISOs now view AI governance and risk management as their responsibility, citing threat actor sophistication as a primary driver. AI is assisting with event triage and data correlation, but verification—especially around AI-generated content—is unreliable, with detection tools struggling against advanced fakes. Insurance mechanisms are becoming productized with prioritized incident response, and legal intelligence is being embedded into MSP workflows. Vendors like N-able, Monjur, SentinelOne, and DocuSign are directly integrating financial, legal, and governance functions into their offerings, fundamentally altering client and vendor relationships. Adjacent stories illustrate volatility in traditional safeguards and the operational reality of adaptive threats. CISA leadership changes indicate instability in public response institutions. AI-powered malware exemplifies the challenge: ESET's PromptSpy uses Gemini to continuously adapt its persistence, outpacing static detection models. Insurance underwriters are increasingly demanding machine-verifiable evidence of controls, using detailed questionnaires to distinguish autonomous AI from marketing claims. The risk is no longer just technical; it is structural. For MSPs and IT leaders, operational posture is now shaped by an ecosystem of embedded warranties, legal terms, governance requirements, and adaptive threats. The ability to document, defend, and productize risk controls becomes a baseline for credibility and insurance eligibility. Failure to build evidence pipelines and clarify vendor-imposed liabilities exposes service providers to compounded risk. The practical implication is a necessity for MSPs to treat governance and detection as measurable, documented capabilities—not assumptions or routine paperwork. Three things to know today: 00:00 CISOs Own Governance, Detectors Lag Fakes, Response Gets Contracted — Accountability Follows 03:14 N-able, SentinelOne, DocuSign Move Risk Management Into the Stack — MSP Terms Follow 05:10 CISOs Want Agentic AI, But Insurers and Adaptive Malware Are Forcing the Timeline 07:32 Why Do We Care? Supported by: CometBackUpSmall Biz Thoughts Community
(Presented by Material Security: We protect your company's most valuable materials -- the emails, files, and accounts that live in your Google Workspace and Microsoft 365 cloud offices.) Three Buddy Problem - Episode 83: Poland's CERT documents a rare, explicit wiper attack on civilians in a NATO country, including detailed attribution of a Russian government op targeting the electric grid in the heart of winter. We examine why this crosses a long-avoided threshold, why attribution suddenly matters again, and what it says about pre-positioned access, vendor insecurity, and the shrinking gap between cyber operations and acts of war. Plus, another Fortinet fiasco, a new batch of Ivanti zero-days under attack, an emergency patch from Microsoft and the return of the mysterious KasperSekrets account. Cast: Juan Andres Guerrero-Saade, Ryan Naraine and Costin Raiu.
Microsoft granted the FBI access to laptops encrypted with BitLocker. The EU opens an investigation into Grok's creation of sexually explicit images. Glimmers of access pierce Iran's internet blackout. Koi Security warns npm fixes fall short against PackageGate exploits. Some Windows 11 devices fail to boot after installing the January Patch Tuesday updates. CISA warns of active exploitation of multiple vulnerabilities across widely used enterprise and developer software. ESET researchers have attributed the cyberattack on Poland's energy sector to Russia's Sandworm. This week's business breakdown. Brandon Karpf joins us to talk space and cyber. CISA sits out RSAC. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Our guest today is cybersecurity executive and friend of the show Brandon Karpf with Dave Bittner and T-Minus Space Daily host Maria Varmazis, for our monthly space and cyber segment. Brandon, Maria and Dave discuss “No more free rides: it's time to pay for space safety.” Selected Reading FBI Accessed Windows Laptops After Microsoft Shared BitLocker Recovery Keys (Hackread) European Commission opens new investigation into X's Grok (The Register) Amid Two-Week Internet Blackout, Some Iranians Are Getting Back Online (New York Times) Hackers can bypass npm's Shai-Hulud defenses via Git dependencies (Bleeping Computer) Microsoft investigates Windows 11 boot failures after January updates (Bleeping Computer) CISA says critical VMware RCE flaw now actively exploited (Bleeping Computer) CISA confirms active exploitation of four enterprise software bugs (Bleeping Computer) ESET Research: Sandworm behind cyberattack on Poland's power grid in late 2025 (ESET) Aikido secures $60 million in Series B funding. (N2K Pro Business Briefing) CISA won't attend infosec industry's biggest conference (The Register) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc. Learn more about your ad choices. Visit megaphone.fm/adchoices