Podcasts about Proofpoint

  • 257PODCASTS
  • 818EPISODES
  • 30mAVG DURATION
  • 5WEEKLY NEW EPISODES
  • Aug 31, 2026LATEST

POPULARITY

20192020202120222023202420252026


Best podcasts about Proofpoint

Show all podcasts related to proofpoint

Latest podcast episodes about Proofpoint

The 20% Podcast with Tyler Meckes
315: Changing The Way People Evaluate And Buy Software with Troy Munson (Enterprise AE, Tailscale)

The 20% Podcast with Tyler Meckes

Play Episode Listen Later Aug 31, 2026 50:37


This week's throwback guest studied Logistics and supply chain management, as well as held roles from Server and Sales Associate in retail, to Named AE. He worked at companies such as Apple, Symantec, MongoDB, Metadata, and Proofpoint, before leading Dimmo, where they are changing the way people evaluate and buy software where you can watch SaaS demos without jumping into sales cycles. Since this conversation, he had the shift to Tailscale as an Enterprise Account Executive. When he isn't at work, he is spending time golfing, and spending time with his family. Without further ado, please join me in welcoming Troy Munson to The 20% Podcast. In this week's episode, we discussed:- His early years- Studying Supply Chain and how it relates now- Discuss his experiences selling software- The lead up to Dimmo- The future of buying softwareEnjoy this week's episode with Troy Munson.I am now in the early stages of writing my first book! It will cover my journey into sales, the lessons learned, and include stories and advice from top sales professionals around the world. I'm excited to share these interviews and bring you along on this journey!Like the show? Subscribe to the email: Subscribe HereI want your feedback! Reach out at 20percentpodcastquestions@gmail.com or connect with me on LinkedIn.If you know anyone who would benefit from this show, please share it! If you have suggestions for guests, let me know!Enjoy the show!

Unchurned
Headless AI vs. CSP: Where CS Insights Should Live ft. Mark Vovsi (Proofpoint)

Unchurned

Play Episode Listen Later Aug 12, 2026 22:20


Want the playbook, not just the conversation? Subscribe for deep-dive, actionable breakdowns from every episode at unchurned.substack.com.Proofpoint had no named accounts. No digital motion. No success plans. Two years later, they've got an AI assistant wired into every customer's data, and an early warning system that catches churn risk a year out.Mark Vovsi, Senior Director, CS Operations - GTM Automation & AI at Proofpoint went from building the CS foundation at Proofpoint to reinventing his own job around AL. This episode isn't a highlight reel. It's Mark walking through what actually got built, in what order, and why. In addition to the debate every CS leader is about to have about where AI-driven insights should even live.---What You'll Learn• Why Proofpoint's CS org started with zero named accounts and what it took to fix it• The 4-stage AI maturity curve: generic AI → connected assistants → automation → predictive risk• How role-based AI assistants get wired into customer 360 data (and why generic ChatGPT falls short)• How Proofpoint auto-generates and auto-refreshes success plans for every customer, every quarter• What an Al-powered early warning system for churn actually looks like under the hood• The headless vs. cockpit debate: should CS insights live in the CSP, Slack/Teams, or Claude/MCP?• Why data hygiene (not AI) is still the real blocker for most CS orgs• How the CSM role is about to change: wider coverage ratios and "jack of all trades" expectations• What Mark looks for when hiring for Al-era CS ops roles---Timestamps0:00 - Preview & Intro2:00 - Meet Mark Vovsi (Proofpoint)2:38 - Building CS from scratch at Proofpoint3:52 - Overview of Proofpoint & It's CS org5:28 - Fixing the data before fixing anything else5:58 - What actually worked: top-down alignment + early adopters6:28 - The shift to Al: from CS Ops to AI/GTM strategy8:52 - Proofpoint's AI maturity model, stage by stage9:30 - Role-based AI assistants wired into customer 360 data10:50 - Auto-generating success plans at scale13:50 - Building an early warning system for churn risk15:00 - Headless AI vs. the CSP cockpit: where should insights live?18:24 - The 12-month vision: catching risk a year out20:00 - How the CSM role and CS hiring is about to change---Josh is writing a book on building customer relationships. Follow his journey and insights at www.joshschachter.com---Where to Find the GuestMark Vovsi: https://www.linkedin.com/in/vovsi/---Where to Find the Hosts: Josh's LinkedIn: https://www.linkedin.com/in/jschachter/Unchurned Substack: https://unchurned.substack.com/

Business of Tech
N-able's Security Revenue Faces Decline as License Portability Undercuts MSP Margins

Business of Tech

Play Episode Listen Later Aug 12, 2026 12:21


The episode details a structural shift for MSPs and IT service providers: the separation of security license resale from the value of human-led security services, and the resulting pricing and margin risks. Companies like N-able, SentinelOne, and SonicWall exemplify how technology offerings and delivery mechanisms are forcing providers to re-examine what differentiates their services beyond the products they resell. N-able's financial results illustrate the risk of relying on product-based security revenue. The company reported a drop in annual recurring revenue, driven by lower renewal rates in Unified Endpoint Management and Endpoint Detection and Response lines—both of which relied on reselling portable licenses, notably SentinelOne's product. In contrast, revenue from services tied to human expertise—through the acquired Adlumen's managed detection and response (MDR)—grew, according to both N-able management and analysts. The episode states that when customers can move licenses without losing service continuity, price becomes the only differentiator, undermining provider margins. Related developments reinforce this dynamic. SonicWall launched a combined antivirus and EDR solution available as both a product and a managed service—explicitly marketed for MSP resale—where SonicWall's analysts handle detection and response. Additionally, Proofpoint expanded its managed services platform, providing security, backup, and compliance through an MSP-oriented, multi-tenant console. These offerings blur the line between manufacturer-managed services and traditional MSP-delivered security work, increasing vendor competition at the service layer. For MSPs and IT leaders, these shifts expose the risk in revenue models that bundle security services with third-party product resale, particularly when those products are easily substitutable. The transcript urges providers to re-evaluate their pricing strategies: separating human service from license cost, justifying it independently, and moving away from device- or seat-based billing. The clear risk is that failing to articulate and defend the value of human-led activities will leave providers vulnerable to vendor undercutting and margin erosion, as seen in recent N-able outcomes. 00:00 Recurring Revenue Went Backwards  03:24 They Stopped Saying RMM 06:04 You Already Own It 09:18 Why Do We Care?  Supported by:  Guardz 

The Cloud Pod
367: Claude introduces DLP, I thought it always stole Data

The Cloud Pod

Play Episode Listen Later Aug 11, 2026 46:00


Welcome to episode 367 of The Cloud Pod, where the forecast is always cloudy! Justin, Ryan, and Matthew are in the studio this week and ready with a lot of news, including passkeys (we know, they've had a rough week), Secrets Manager, Vector Search, and Glimmer (no, not my second favorite character from She-Ra), and even…wait for it…undersea cable news!  We've got a lot to cover, so let's get started!  Titles we almost went with this week AWS Secrets Manager Jenkins Rotation Finally Claude Enterprise Hooks a Ride on Data Loss Prevention Passkeys Take the Wheel, SMS Rides Off Into the Sunset Claude Code Says Trust Falls Are Over Muse Glimmer Shines While Meta’s Wallet Dims Zuckerberg Bets Big on Open Weights, Loses on Free Cash Flow AI is persistently in the news How many ways are there to run vector search in AWS, now 1 more Vector Search is the new Docker on AWS… how many ways are there to run it AWS Says “You get a Vector Search, and you get a Vector Search” You say you’re a Cloud Azure, but “Azure Network Router Appliance” says otherwise Claude now tells the world, I did the AI Slop Open, Closed, Open; Zuckerberg is on the AI Revolving Door Anthropic triples everyone’s productivity with Automode A big thanks to this week's sponsors: We're sponsorless! Want to get your brand, company, or service in front of a very enthusiastic group of cloud news seekers? You've come to the right place! Send us an email or hit us up on our Slack channel for more info. AI Is Going Great – or How ML Makes Money  01:40 Inference hooks: inline data loss prevention for Claude Enterprise  Anthropic launched inference hooks in beta for Claude Enterprise, providing inline data loss prevention across chat, Claude Code, Claude Cowork, and other Enterprise surfaces through a single configuration point. Technical approach: every inference request routes through a signed WebSocket connection to a customer-controlled security server; Claude sends the prompt and context before generation begins and waits for an allow/deny verdict before proceeding. The same inspection applies to tool call responses, including those from MCP connectors, skills, and plugins. The feature uses an open, webhook-based protocol with a published schema, allowing integration with existing DLP vendors such as Netskope, Palo Alto Networks, Proofpoint, and Zscaler, or custom in-house security servers, without requiring separate per-product integration work. Rollout controls include shadow mode (log without blocking), role-based exclusions, and percentage-based rollouts, along with configurable failure-policy tolerance and timeouts to match organizational risk requirements. This addresses a gap where inline enforcement was previously limited to Claude Code’s client-side hooks, giving compliance teams a unified enforcement layer for sensitive data across all Claude Enterprise channels.  Documentation is available

Hacking Humans
Class is in session—for cybercriminals. [OMITB]

Hacking Humans

Play Episode Listen Later Aug 4, 2026 49:58


Welcome in! You've entered, Only Malware in the Building. Join us each month to sip tea and solve mysteries about today's most interesting threats. Your host is ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Selena Larson⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠, ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Proofpoint⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠ intelligence analyst and host of their podcast ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠DISCARDED⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠. Inspired by the residents of a building in New York's exclusive upper west side, Selena is joined by her co-hosts ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠N2K Networks⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠ ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Dave Bittner⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠ and ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Keith Mularski⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠, former FBI cybercrime investigator and now Chief Global Ambassador at ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Qintel⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠. Being a security researcher is a bit like being a detective: you gather clues, analyze the evidence, and consult the experts to solve the cyber puzzle. This week, Today, while Keith is off, Dave and Selena kick off a back-to-school special, exploring the cyber threats students, parents, educators, and universities should have on their radar. They examine the rise in job scams targeting university communities, discuss recent espionage activity aimed at higher education institutions in the U.S. and Canada, and look at how cybercriminals prey on younger audiences through online games, YouTube, and social media. From fake game cracks delivering information stealers to sextortion schemes targeting teens, they break down the tactics attackers are using and share practical advice for staying safe as the new school year begins. Sources:  ⁠⁠⁠⁠⁠ Job Scams Using Bioscience Lures Target Universities One Email Closer to the Edge: UNK_MassTraction & the Physics of Exploitation

Secure Ventures with Kyle McNulty
Tracebit | CEO Andy Smith on Modern Cyber Deception

Secure Ventures with Kyle McNulty

Play Episode Listen Later Aug 4, 2026 44:10


Happy BlackHat to those who celebrate!Andy Smith is founder and CEO of Tracebit. Tracebit sells a cyber deception platform to lure attackers into targeting intentionally vulnerable targets, giving valuable information to defenders. Andy argues that as AI-driven attacks increase in exploit speed and complexity, deception will play more of a role than ever to provide early detection to defenders. Before Tracebit, Andy worked as a developer, including head of engineering at Tessian which was acquired by Proofpoint in 2022. In the episode we touch on his thesis for improved deception, his bike trip down the west coast of the US, his descent into cold outreach, including how he is successful, and more.

Only Malware in the Building
Class is in session—for cybercriminals.

Only Malware in the Building

Play Episode Listen Later Aug 4, 2026 49:58


Welcome in! You've entered, Only Malware in the Building. Join us each month to sip tea and solve mysteries about today's most interesting threats. Your host is ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Selena Larson⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠, ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Proofpoint⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠ intelligence analyst and host of their podcast ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠DISCARDED⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠. Inspired by the residents of a building in New York's exclusive upper west side, Selena is joined by her co-hosts ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠N2K Networks⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠ ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Dave Bittner⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠ and ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Keith Mularski⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠, former FBI cybercrime investigator and now Chief Global Ambassador at ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Qintel⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠. Being a security researcher is a bit like being a detective: you gather clues, analyze the evidence, and consult the experts to solve the cyber puzzle. This week, Today, while Keith is off, Dave and Selena kick off a back-to-school special, exploring the cyber threats students, parents, educators, and universities should have on their radar. They examine the rise in job scams targeting university communities, discuss recent espionage activity aimed at higher education institutions in the U.S. and Canada, and look at how cybercriminals prey on younger audiences through online games, YouTube, and social media. From fake game cracks delivering information stealers to sextortion schemes targeting teens, they break down the tactics attackers are using and share practical advice for staying safe as the new school year begins. Sources:  ⁠⁠⁠⁠⁠ Job Scams Using Bioscience Lures Target Universities One Email Closer to the Edge: UNK_MassTraction & the Physics of Exploitation

Security Conversations
Proofpoint's Greg Lesnewich on Laundry Bear, ‘Half-Click' Exploits, and Magnets of Threats

Security Conversations

Play Episode Listen Later Jul 31, 2026 206:39


(Presented by Thinkst Canary: Most Companies find out way too late that they've been breached. Thinkst Canary changes this. Deploy Canaries and Canarytokens in minutes and then forget about them. Attackers tip their hand by touching 'em giving you the one alert, when it matters. With zero admin overhead and almost no false-positives, Canaries are deployed (and loved) on all 7 continents.) Three Buddy Problem - Episode 107: Proofpoint's Greg Lesnewich joins the show to break down Laundry Bear, the "half-click" webmail exploits that let a Russian GRU cluster hack inboxes the moment an email was opened, and what it took to publish alongside the NSA, FBI and sixteen allied agencies. Plus, Anthropic and OpenAI both admit their models escaped test sandboxes and popped real companies, why JAGS wants the CFAA burned down and vulnerable devices bricked, and a heartfelt detour into how threat hunters actually build intuition and skills. Cast: Greg Lesnewich, Juan Andres Guerrero-Saade, Ryan Naraine and Costin Raiu. Timestamps: 0:00 Sponsor - Thinkst Canary 1:34 Greg Lesnewich introduces the Proofpoint threat-hunting team 5:23 Inside the NSA ‘Laundry Bear' advisory 7:15 What does "half-click" mean? 9:58 Laundry Bear's Zimbra exploit: DNS exfil and app-specific password persistence 12:59 Ferrari model numbers, F1 UNC names, and ESET's Operation RoundPress 17:05 Targeting Ukraine, US universities, and magnetic fusion research 19:34 How threat hunters actually build intuition 32:35 Systems thinking, Donella Meadows, and Costin's laptop under the dinner table 54:48 The dopamine hit of a real find and the deleted "never mind" messages 1:00:42 Magnets of threats: under 1% of customers ever see an APT 1:25:21 Getting detections into the product, and coordinating a release with NSA 1:53:22 Anthropic and OpenAI models breaking out of the eval sandbox 2:17:45 The case for killing the CFAA and bricking vulnerable devices 2:43:44 AI in the lab, malware paleontology, Google's new names, and AngrySpark

Cyber Security Today
OpenAI's rogue agent hit more victims, attackers hit 30 Minnesota water systems, Russian crew delivers weaponized e-mails in Exchange

Cyber Security Today

Play Episode Listen Later Jul 31, 2026 11:38


OpenAI 'Rogue Agent' Fallout, Minnesota Water Systems Hit, Exchange OWA Zero-Click Mailbox Takeover   David Shipley covers multiple security stories: the OpenAI "rogue agent" incident expands as Modal Labs says a customer's exposed endpoint was used as a launchpad in attacks on Hugging Face, while critics cite missing zero trust/defense-in-depth and disabled safeguards; Bruce Schneier and Bargath Raghaven label this the "genie effect" and propose a "genie coefficient" to measure instruction-to-outcome gaps.   Minnesota IT Services reports more than 30 community water systems hit in a coordinated OT attack July 26–27, with some running manually, as agencies assist and warnings persist about Iranian-linked PLC targeting; Canada also reports a NoName intrusion claim.   Proofpoint details Laundry Bear exploiting an Exchange OWA XSS (CVE-2026-42897) to maintain mailbox access even after password resets. MCBS reports a 2025 breach affecting 1.261M people. Lava finds ~25,000 internet-exposed IPMI/BMCs leaking crackable hashes.   00:00 Headlines and intro 00:29 OpenAI rogue agent fallout 02:18 Genie effect and benchmarks 03:29 Minnesota water systems hit 05:02 Iran-linked PLC warnings 06:23 Exchange OWA mailbox backdoor 08:24 Medical billing breach tally 09:43 IPMI BMCs exposed online 11:00 Wrap-up and next episodes

Choses à Savoir TECH
Des millions de comptes compromis sur Microsoft ?

Choses à Savoir TECH

Play Episode Listen Later Jul 23, 2026 2:29


Une nouvelle technique d'attaque inquiète les spécialistes de la cybersécurité. Son nom : l'« OAuth Client ID Spoofing ». Selon Proofpoint, elle permet à des pirates de tester massivement des identifiants et des mots de passe sur Microsoft Entra ID, tout en restant presque invisibles dans les journaux de sécurité. Microsoft Entra ID, anciennement Azure Active Directory, gère l'authentification des utilisateurs et des applications. Chaque logiciel autorisé possède normalement un identifiant unique, appelé « client ID », comparable à un badge présenté à l'entrée d'un bâtiment. Les attaquants ont toutefois découvert qu'ils pouvaient envoyer des requêtes avec des identifiants falsifiés, inexistants ou malformés.Pour reproduire la méthode, Proofpoint a utilisé le protocole ROPC, qui transmet directement un nom d'utilisateur et un mot de passe au service d'authentification. Le danger vient des réponses renvoyées par Microsoft. Selon le code d'erreur obtenu, l'attaquant peut déterminer si le compte existe, si le mot de passe est incorrect ou si les identifiants sont valides mais que l'application présentée n'est pas reconnue. Ce dernier cas est particulièrement préoccupant : il permet de confirmer qu'un couple identifiant-mot de passe fonctionne, sans générer de connexion réussie. Dans les registres, seul un numéro d'application apparaît, sans nom associé. Les outils chargés de surveiller une application précise peuvent donc passer complètement à côté. Certaines règles d'accès conditionnel risquent également de ne pas s'appliquer. Proofpoint affirme avoir observé deux campagnes réelles. La première, baptisée UNK_pyreq2323, a débuté le 14 janvier 2026 depuis des serveurs Amazon Web Services. Elle aurait utilisé plus de 700 000 identifiants falsifiés pour viser plus d'un million de comptes dans près de 4 000 organisations. Environ 28 % des comptes ciblés auraient été automatiquement verrouillés.Une seconde campagne, UNK_OutFlareAZ, a débuté en décembre 2025 depuis une infrastructure Cloudflare. Elle aurait visé plus de deux millions d'utilisateurs avec 3,7 millions de faux identifiants. Les pirates semblent notamment tester des noms courants, comme jsmith ou msmith, dans des centaines d'entreprises. Proofpoint recommande donc de surveiller les connexions sans nom d'application et de ne plus considérer certains codes d'erreur comme de simples échecs sans conséquence. Hébergé par Acast. Visitez acast.com/privacy pour plus d'informations.

Easy Prey
When Trust Becomes a Trap

Easy Prey

Play Episode Listen Later Jul 22, 2026 52:58


Most people use technology all day without giving much thought to what is happening behind the screen. We trust routers that may not have been updated in years, depend on internet systems few of us understand, and now turn to artificial intelligence for everything from travel plans to home repairs. That convenience comes with tradeoffs. In this episode, we look at the weaknesses built into our connected world and what happens when our technical knowledge fails to keep pace with the technology surrounding us. Sherrod DeGrippo leads threat intelligence for Unit 42 at Palo Alto Networks, where she oversees teams working to identify and respond to increasingly complex cyber threats. During more than two decades in information security, she has held senior leadership roles at Microsoft and Proofpoint, along with positions at Nexum, Symantec, Secureworks, and the National Nuclear Security Administration. Sherrod was named Cyber Security Woman of the Year in 2022 and regularly shares her expertise at industry conferences and through outlets including BBC News, The Wall Street Journal, CNN, and The New York Times. She is also the author of *Threat Driven Software Development: Defending Modern Online Services*. We discuss how outdated home routers become tools for criminal and nation-state attacks, what could happen as technical knowledge disappears, and why foundational internet systems may be more vulnerable than people realize. Sherrod also explains why the greatest danger from AI may not be a dramatic technological disaster, but the gradual loss of human connection as people choose frictionless answers over real conversations. Along the way, she shares practical examples of where AI genuinely helps, where its limits become obvious, and why slowing down still matters when emotion or urgency begins driving a decision. Show Notes: [01:48] Sherrod introduces herself and traces her 23-year career from government network security to threat intelligence. [03:00] An early lesson in buffer overflows sparked a lasting interest in both hacking and protecting systems. [05:10] Growing up around AT&T gave Sherrod firsthand experience with telephone networks, copper lines, and beige boxing. [08:17] Technology has shifted from something people opened and explored into consumer devices few people truly understand. [11:24] As technical knowledge disappears, the people who understand how systems actually work are becoming increasingly rare. [13:41] Older internet users often understood where their data traveled, while today's devices constantly communicate in the background. [16:22] Network security remains critical because once malicious traffic reaches a device, the problem has already become much larger. [17:57] Outdated home routers provide an attractive attack surface for criminals and foreign governments. [20:12] The conversation turns to the fragility of DNS, internet protocols, and the systems supporting the global network. [22:13] Chris shares his experience with denial-of-service attacks and seeing legitimate online services exploited by malware. [25:48] Sherrod explains why AI's greatest danger may be the gradual loss of human relationships rather than a dramatic physical threat. [29:23] AI works well for tedious tasks, but human connection, creativity, and judgment should not be handed over so easily. [31:35] Living intentionally means deciding what experiences matter instead of allowing technology or other outside forces to decide for us. [34:10] Frictionless technology may leave people more vulnerable to scams by training them to expect immediate and effortless results. [35:33] Social engineering uses modern tools, but manipulation, espionage, and theft have existed for thousands of years. [38:14] AI may eliminate certain jobs while also giving people more time to focus on customers, relationships, and other human-centered work. [40:44] A furnace repair shows how AI can guide basic troubleshooting and reduce the need for some professional diagnostic visits. [43:08] AI can help someone become competent in many areas, but having access to it does not make anyone an expert. [45:44] Used intentionally, AI can remove unwanted planning and create more opportunities for people to spend time together. [47:18] Strong prompts, detailed skill files, and personalized instructions may become more valuable than traditional prompt engineering. [49:10] A gift card scam demonstrates how fear and urgency can push someone to ignore repeated warnings from others. [51:30] Sherrod advises pausing whenever a strong emotion begins driving an unusual financial or personal decision.  Thanks for joining us on Easy Prey. Be sure to subscribe to our podcast on iTunes and leave a nice review.  Links and Resources: Podcast Web Page Facebook Page whatismyipaddress.com Easy Prey on Instagram Easy Prey on Twitter Easy Prey on LinkedIn Easy Prey on YouTube Easy Prey on Pinterest Sherrod DeGrippo Sherrod DeGrippo - LinkedIn Palo Alto Networks Unit 42 Threat Driven Software Development: Defending Modern Online Services

The CyberWire
For hackers, sharing is caring.

The CyberWire

Play Episode Listen Later Jul 16, 2026 30:28


CISA warns of active SharePoint attacks. The NSA pushes coordinated vulnerability disclosure. ClickLock Stealer targets macOS. Splunk and Zoom patch critical flaws. Spirals ransomware strikes in under 24 hours. New Windows evasion techniques emerge. LabubaRAT poses as NVIDIA software. 23andMe settles over its 2023 breach. Plus, a look back at one of the most audacious data center heists ever pulled off. Our guest is Ryan Kalember, Chief Strategy Officer at Proofpoint, discussing why agentic AI is creating a new insider threat. Near, far, wherever you are…the scam must go on. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Today we are joined by Ryan Kalember, Chief Strategy Officer at Proofpoint, and he is discussing why agentic AI is creating a new insider threat. Selected Reading CISA urges immediate SharePoint hardening as exploits mount (CSO Online) NSA joins CISA and Others in Releasing the Cybersecurity Information Sheet “Establishing a Coordinated Vulnerability Disclosure Program to Work with Security Researchers” (NSA) ‘ClickLock Stealer' Bypasses macOS Security With Social Engineering, Process Killing (SecurityWeek) Splunk, Zoom Patch Critical Vulnerabilities (SecurityWeek) New Spirals ransomware encrypts victim network in under 24 hours (Bleeping Computer) Bind Link Abuse: One Windows Feature, Many Ways to Blind Your EDR (Bitdefender) LabubaRAT: A Rust Based Remote Access Tool Masquerading as NVIDIA Software (Blackpoint Cyber) 23andMe reaches $18 million settlement with states for massive breach (The Record) How a Gang of Thieves Pulled Off a Multimillion-Dollar Data Center Heist (The New York Times) Fake Céline Dion Paris Tickets Sold on Facebook and Ticketmaster Clones (Hackread) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc. Learn more about your ad choices. Visit megaphone.fm/adchoices

Only Malware in the Building
Nothing left to StealC.

Only Malware in the Building

Play Episode Listen Later Jul 7, 2026 41:01


Welcome in! You've entered, Only Malware in the Building. Join us each month to sip tea and solve mysteries about today's most interesting threats. Your host is ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Selena Larson⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠, ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Proofpoint⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠ intelligence analyst and host of their podcast ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠DISCARDED⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠. Inspired by the residents of a building in New York's exclusive upper west side, Selena is joined by her co-hosts ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠N2K Networks⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠ ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Dave Bittner⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠ and ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Keith Mularski⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠, former FBI cybercrime investigator and now Chief Global Ambassador at ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Qintel⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠. Being a security researcher is a bit like being a detective: you gather clues, analyze the evidence, and consult the experts to solve the cyber puzzle. This week, This week, our hosts dive into the recent Operation Endgame disruptions targeting the SocGholish and StealC malware ecosystems, exploring what these coordinated takedowns mean for the evolving web injection threat landscape. They unpack how web inject campaigns have become a favored entry point for cybercriminals, enabling everything from credential theft to ransomware deployment, and why taking down infrastructure is only one piece of the puzzle. Plus, they discuss what defenders should watch for next as attackers adapt and rebuild. Sources:  ⁠⁠⁠ StealC video SocGholish video⁠ Sayonara, SocGholish: Operation Endgame Disrupts Major Cybercrime Operation StealC You Later: Proofpoint and IBM X-Force Support Operation Endgame Disruptions StealC and Amadey: Breaking down infostealers and the cybercrime services that deliver them Global cyber strike disrupts SocGholish, Amadey, and StealC malware networks

Partnerships Unraveled
Jason Henry - The channel opportunity nobody talks about

Partnerships Unraveled

Play Episode Listen Later Jul 7, 2026 29:06 Transcription Available


Send us Fan MailIn this episode of Partnerships Unraveled, we sit down with Jason Henry, Vice President of MSP Platform Sales for the Americas at Hornetsecurity. With three decades of enterprise sales leadership behind him and a mandate to build the Americas partner business from scratch, Jason brings a fresh lens to where the channel opportunity really lives.Jason opens with the story of Hornetsecurity's new chapter. After being acquired by Proofpoint late last year, the company is now making the small-to-medium business and managed service provider space a true focus, and Jason is leading the Americas build. His first 90 days have centered on two things: the people and the partners. Deep listening sessions with top partners have surfaced honest feedback on what is working and where the biggest opportunities sit. Partners, Jason has found, are genuinely invested in the mission, and that shared excitement is one of the strongest foundations to build a channel-first business on.From there, the conversation turns to where the space is heading. Jason makes the case that AI will have an even bigger impact on the small-to-medium business market than the enterprise, because it lets small businesses do more with far fewer resources. That opens up a real evolution for managed service providers, who are moving from technology support into a business consultant role for the founders and CEOs they serve. The providers who lean into this shift, deliver agent-based services, and lead their customers through the transformation are the ones set to capture the biggest opportunity of the next few years.Jason closes on what he's carried through three decades of sales leadership. Believe in your people, build great teams, support them well, and build the next generation of leaders. That's how the businesses that last actually get built._________________________Learn more about Channext

ScanNetSecurity 最新セキュリティ情報
日本の AI 関連インシデント経験は 47%、セキュリティ対策の遅れ浮き彫り ~ Proofpoint 調査

ScanNetSecurity 最新セキュリティ情報

Play Episode Listen Later Jun 21, 2026 0:10


日本プルーフポイント株式会社は6月11日、「2026 AI and Human Risk Landscape」レポートの日本語版を発表した。

Business of Tech
Government AI Shutdown Exposes Hidden Vendor Dependencies for MSPs

Business of Tech

Play Episode Listen Later Jun 16, 2026 11:57


A pronounced infrastructure dependence on third-party AI models has emerged across the MSP ecosystem, largely due to the rapid adoption and integration of AI-powered features within vendor products. This structural shift is increasingly opaque, as providers are sold features rather than transparent access to underlying models, leaving MSPs exposed to changes in technologies and policies enacted upstream by vendors or regulators. The episode highlights how this dependency extends to delivery teams and end clients, with operational continuity tightly linked to decisions and actions outside the MSP's direct control. The most consequential development referenced is Anthropic's release and rapid withdrawal of its Fable 5 AI model following a directive from the U.S. Commerce Department, which ordered a cutoff of model access to foreign nationals within 72 hours of public launch. According to published benchmarks, Fable 5 surpassed GPT 5.5 in performance, but the government-mandated suspension exposed how quickly model access can be rescinded. The policy move immediately impacted any MSP or client with offshore or nearshore staff relying on AI features invisibly powered by that model. Further supporting the central theme, companies such as PAX8, Enforcer, and CloudRadio are embedding AI capabilities into platforms used by MSPs to manage Microsoft 365 environments, automate ticketing, and support scalable client operations. In parallel, vendors like Proofpoint are integrating compliance solutions directly with AI model APIs, further entwining risk management tools with the same core AI infrastructures. A Netrio survey cited in the episode found that while 82% of mid-market IT leaders have AI in production, only 26% report organization-wide governance, highlighting an accountability and visibility gap. Operationally, MSPs face heightened contract and vendor risk. Most lack an accurate inventory of which AI models underpin their services and how rapidly these dependencies can be affected by regulatory directives or vendor shifts. The discussion underscores the need for explicit procurement protocols, delivery mapping, and outage runbooks that account for opaque model dependencies. As clients seek greater transparency and contractual assurances regarding model use and continuity, MSPs who anticipate and document these dependencies may be positioned to reduce exposure and establish clearer accountability. 00:00 Switched Off  03:19 Painted Over 05:20 Govern or Absorb 08:41 Why Do We Care?  Supported by: Pax8 Sign up for the SMB Online Conference: www.smbonlineconference.com

Hacking Humans
Trusting the wrong package. [Only Malware in the Building]

Hacking Humans

Play Episode Listen Later Jun 2, 2026 46:54


Welcome in! You've entered, Only Malware in the Building. Join us each month to sip tea and solve mysteries about today's most interesting threats. Your host is ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Selena Larson⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠, ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Proofpoint⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠ intelligence analyst and host of their podcast ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠DISCARDED⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠. Inspired by the residents of a building in New York's exclusive upper west side, Selena is joined by her co-hosts ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠N2K Networks⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠ ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Dave Bittner⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠ and ⁠⁠⁠⁠⁠⁠⁠⁠⁠Keith Mularski⁠⁠⁠⁠⁠⁠⁠⁠⁠, former FBI cybercrime investigator and now Chief Global Ambassador at ⁠⁠⁠⁠⁠⁠⁠⁠⁠Qintel⁠⁠⁠⁠⁠⁠⁠⁠⁠. Being a security researcher is a bit like being a detective: you gather clues, analyze the evidence, and consult the experts to solve the cyber puzzle. This week, our hosts dive into the evolving threat of software supply chain attacks and the growing risks facing the open-source ecosystem. As developers increasingly rely on third-party packages and AI-powered coding tools, attackers are finding new ways to abuse trusted software to reach a wider range of targets. The discussion explores why these attacks are becoming more common, what recent incidents reveal about the state of software security, and what organizations can do to better protect themselves. Sources:  ⁠ Shai-Hulud worm returns stronger and more automated than ever before⁠ ‘Mini Shai-Hulud' malware compromises hundreds of open-source packages in sprawling supply-chain attack⁠ What We Learned: Axios NPM Supply Chain Compromise Emergency Briefing Your AI Gateway Was a Backdoor: Inside the LiteLLM Supply Chain Compromise

Only Malware in the Building
Trusting the wrong package.

Only Malware in the Building

Play Episode Listen Later Jun 2, 2026 46:54


Welcome in! You've entered, Only Malware in the Building. Join us each month to sip tea and solve mysteries about today's most interesting threats. Your host is ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Selena Larson⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠, ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Proofpoint⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠ intelligence analyst and host of their podcast ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠DISCARDED⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠. Inspired by the residents of a building in New York's exclusive upper west side, Selena is joined by her co-hosts ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠N2K Networks⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠ ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Dave Bittner⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠ and ⁠⁠⁠⁠⁠⁠⁠⁠⁠Keith Mularski⁠⁠⁠⁠⁠⁠⁠⁠⁠, former FBI cybercrime investigator and now Chief Global Ambassador at ⁠⁠⁠⁠⁠⁠⁠⁠⁠Qintel⁠⁠⁠⁠⁠⁠⁠⁠⁠. Being a security researcher is a bit like being a detective: you gather clues, analyze the evidence, and consult the experts to solve the cyber puzzle. This week, our hosts dive into the evolving threat of software supply chain attacks and the growing risks facing the open-source ecosystem. As developers increasingly rely on third-party packages and AI-powered coding tools, attackers are finding new ways to abuse trusted software to reach a wider range of targets. The discussion explores why these attacks are becoming more common, what recent incidents reveal about the state of software security, and what organizations can do to better protect themselves. Sources:  ⁠ Shai-Hulud worm returns stronger and more automated than ever before⁠ ‘Mini Shai-Hulud' malware compromises hundreds of open-source packages in sprawling supply-chain attack⁠ What We Learned: Axios NPM Supply Chain Compromise Emergency Briefing Your AI Gateway Was a Backdoor: Inside the LiteLLM Supply Chain Compromise

Business of Tech
AI Integration Into PSA and Security Platforms Forces New Governance Demands on MSPs

Business of Tech

Play Episode Listen Later May 15, 2026 11:53


The core structural shift described in this episode is the integration of AI as an active workflow actor within managed service environments, not simply as an isolated tool. This mechanism alters the governance and accountability requirements for MSPs, as AI now interacts directly with core business platforms and operational data. Companies like Microsoft are embedding AI features—such as Copilot and a legal AI agent—across productivity and security environments, while reports from Axios Future of Cybersecurity and The Register highlight that AI activity is increasingly touching managed identity, email, data, and security infrastructures. The episode's primary evidence centers on the adoption of AI-driven productivity and legal tools within Microsoft 365, with broad rollout timelines targeting early June. Microsoft's deployment of legal AI agents in Word—as outlined by The Register and Thoreau—demonstrates that AI is being implemented to review contracts, draft language, and check citations, embedding itself into sensitive business workflows. Additionally, Proofpoint's formation of an MSP business unit around 365 security further reflects this shift, consolidating risk and workflow management where client data, identity, and security converge. Supporting developments reinforce this trend of workflow centralization and accountability ambiguity. Vendors are introducing dashboards—such as Anthropic's Claude code agent view—that offer improved visibility into AI-driven processes; however, as noted, visibility alone does not constitute governance. The emergence of platforms like Halo PSA and features from JumpCloud exemplify the market response, where vendors and MSPs are being forced to tighten control and monitoring around AI-driven work, including automation, ticketing, and remediation workflows. The episode notes that unmanaged automation creates governance risks that operators must close. The practical implication for MSPs is a set of new operational burdens: rising margin pressure from unpriced AI governance work, contract risk if responsibilities for AI-generated actions remain undefined, and new demands for auditability, evidence retention, and workflow documentation. Providers must build inventories not only of AI tools but also the workflows they touch, define explicit service scope, and establish pricing models for governance functions. The operational tradeoff is an increasing need for infrastructure and process maturity, as the expectation of transparent, accountable AI-driven work is now a baseline for client trust and risk management. 00:00 Managed AI Risk  03:50 Scope or Absorb 06:03 Four MSP Pressures 08:35 Why Do We Care?  Supported by:  MoovilaHaloPSA JumpCloud 

Business of Tech
AI Accelerates Exploit Creation and Evidence Burden for MSPs, Says Google and Proofpoint

Business of Tech

Play Episode Listen Later May 13, 2026 13:55


The central structural shift identified is the acceleration and scaling of cyber risks due to artificial intelligence, which turns formerly expert-driven security processes into repeatable, rapid workflows. Major threat intelligence units, including Google's Threat Intelligence group, are now documenting the use of AI in both identifying and weaponizing software vulnerabilities. The landscape is further shaped by the proliferation of AI-generated and AI-assisted online content, contributing to an environment where traditional verification and control mechanisms are less reliable. The episode presents concrete evidence: Google reported criminal hackers leveraging AI models—explicitly noting the use of non-Google technology—to discover a previously unknown zero day, while The Verge and Wired highlighted AI-assisted attempts to bypass multi-factor authentication and the impact of synthetic content even within cybercrime forums. Research covered by 404 Media documented that by mid-2025, a third of newly published websites were AI-influenced. These observed changes drive threat intelligence teams to treat AI as a working hypothesis in live investigations. Additional supporting developments reinforce the broadening security and operational impact. Tools such as Proofpoint's Prism Investigator and OpenAI's Daybreak show the push toward automated threat detection, investigation, and reasoning pipelines, altering expectations from detection to defensible reconstruction and evidence generation. Analysis of supply chain compromises—such as tampered software installers and malware leveraging already-exposed cloud systems—demonstrates how automation reduces defender response windows while increasing operational pressure on providers. Reports from Small Biz Trends and channel Life show significant implementation gaps, with only a minority of small businesses deploying password managers, and a wide disparity between optimism and readiness for AI-powered security. For MSPs and IT leaders, these trends tighten operational accountability. The tradeoff shifts from focusing on technology stacks to delivering concrete evidence of patch application, identity verification, data retention, and audit support. Providers face increasing pressure to standardize verification workflows, reduce patch validation cycles, and make evidence retention a default process. The operational complexity intensifies—either the MSP develops controls to govern automation and evidentiary rigor, or becomes the default risk absorber for ambiguous, fast-moving attack paths shaped by both client and attacker use of automation.   00:00 Zero-Day  04:06 Speed Gap 06:25 Prove It 10:27 Why Do We Care?  Supported by:  Moovila Zero Networks   

The CyberWire
The spy who logged me in. [Research Saturday]

The CyberWire

Play Episode Listen Later May 9, 2026 2:45


Mark Kelly, Staff Threat Researcher at Proofpoint, is discussing their work on "I'd come running back to EU again: TA416 resumes European government espionage campaigns." China-linked threat group TA416 has resumed large-scale phishing and malware campaigns targeting European governments, diplomatic missions tied to the EU and NATO, and more recently Middle Eastern entities following the outbreak of conflict in Iran. The group has continually evolved its tactics between mid-2025 and early 2026, using techniques like fake Cloudflare verification pages, Microsoft OAuth redirect abuse, and malicious C# project files to deliver customized PlugX malware through spearphishing campaigns. Researchers say the renewed activity reflects shifting geopolitical priorities tied to EU-China tensions, the Russia-Ukraine war, and instability in the Middle East, while highlighting TA416's ongoing focus on intelligence gathering against diplomatic networks. The research and executive brief can be found here: I'd come running back to EU again: TA416 resumes European government espionage campaigns Learn more about your ad choices. Visit megaphone.fm/adchoices

Research Saturday
The spy who logged me in.

Research Saturday

Play Episode Listen Later May 9, 2026 24:03


Mark Kelly, Staff Threat Researcher at Proofpoint, is discussing their work on "I'd come running back to EU again: TA416 resumes European government espionage campaigns." China-linked threat group TA416 has resumed large-scale phishing and malware campaigns targeting European governments, diplomatic missions tied to the EU and NATO, and more recently Middle Eastern entities following the outbreak of conflict in Iran. The group has continually evolved its tactics between mid-2025 and early 2026, using techniques like fake Cloudflare verification pages, Microsoft OAuth redirect abuse, and malicious C# project files to deliver customized PlugX malware through spearphishing campaigns. Researchers say the renewed activity reflects shifting geopolitical priorities tied to EU-China tensions, the Russia-Ukraine war, and instability in the Middle East, while highlighting TA416's ongoing focus on intelligence gathering against diplomatic networks. The research and executive brief can be found here: I'd come running back to EU again: TA416 resumes European government espionage campaigns Learn more about your ad choices. Visit megaphone.fm/adchoices

The CyberWire
A wolf in admin clothing. [Research Saturday]

The CyberWire

Play Episode Listen Later Apr 11, 2026 2:45


Today we are joined by Selena Larson, Threat Researcher from Proofpoint research team and co-host of Only Malware in the Building, talking about their work on "(Don't) TrustConnect: It's a RAT in an RMM hat." Proofpoint uncovered TrustConnect, a malware-as-a-service platform posing as a legitimate remote monitoring and management (RMM) tool, but actually functioning as a remote access trojan (RAT) sold to cybercriminals for $300/month. The operation used a fake business website, legitimate-looking certificates, and branded installers (like fake Microsoft Teams or Zoom apps) to trick victims, while providing attackers with full remote control, file transfer, and surveillance capabilities. Although parts of its infrastructure were disrupted, the threat actor quickly rebounded with new variants, highlighting both the resilience of the operation and its deep ties to the broader cybercriminal ecosystem abusing RMM tools. The research and executive brief can be found here: (Don't) TrustConnect: It's a RAT in an RMM hat Learn more about your ad choices. Visit megaphone.fm/adchoices

Research Saturday
A wolf in admin clothing.

Research Saturday

Play Episode Listen Later Apr 11, 2026 24:44


Today we are joined by Selena Larson, Threat Researcher from Proofpoint research team and co-host of Only Malware in the Building, talking about their work on "(Don't) TrustConnect: It's a RAT in an RMM hat." Proofpoint uncovered TrustConnect, a malware-as-a-service platform posing as a legitimate remote monitoring and management (RMM) tool, but actually functioning as a remote access trojan (RAT) sold to cybercriminals for $300/month. The operation used a fake business website, legitimate-looking certificates, and branded installers (like fake Microsoft Teams or Zoom apps) to trick victims, while providing attackers with full remote control, file transfer, and surveillance capabilities. Although parts of its infrastructure were disrupted, the threat actor quickly rebounded with new variants, highlighting both the resilience of the operation and its deep ties to the broader cybercriminal ecosystem abusing RMM tools. The research and executive brief can be found here: (Don't) TrustConnect: It's a RAT in an RMM hat Learn more about your ad choices. Visit megaphone.fm/adchoices

Hacking Humans
When “opportunity” knocks, don't answer.

Hacking Humans

Play Episode Listen Later Apr 9, 2026 49:09


This week, hosts of N2K CyberWire ⁠⁠⁠⁠⁠⁠⁠Maria Varmazis⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠ and⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠ ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Dave Bittner⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠ alongside ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Joe Carrigan⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠ are discussing the latest in social engineering scams, phishing schemes, and criminal exploits that are making headlines. Your favorite follow up story is back, this time Sue from Australia discusses why Joe's hen is losing feathers. Dave's story is on a sophisticated LinkedIn phishing scam that tricks professionals with fake notifications and counterfeit login pages to steal credentials. Joe discusses a bizarre Everest scam where climbers and Sherpas were targeted with fake rescue schemes, highlighting the surprisingly high number of visitors versus summiters. Maria has the story of IRS and tax-related scams warning taxpayers about ghost preparers, urgent payment demands, and fraudulent contact attempts, with Proofpoint noting the use of remote monitoring tools in 40% of 2026 cases. Our catch of the day comes from Reddit, where a likely “stranded in the woods” scam involving a man named Michael begins to unfold but quickly unravels after he overwhelms the interaction with constant ChatGPT-style questioning. Resources and links to stories: ⁠LinkedIn Phishing Scam Uses Fake Notifications to Hijack Accounts Everest guides accused of poisoning foreign climbers to force fake rescues in $20m scam Surge in sophisticated tax scams reported by BBB ahead of deadline Security brief: tax scams aim to steal funds from taxpayers The Guy in the Woods - Seduction on Scrabble - Part 1 ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Have a Catch of the Day you'd like to share? Email it to us at ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠hackinghumans@n2k.com⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠.

Only Malware in the Building
Who's logging in?

Only Malware in the Building

Play Episode Listen Later Apr 7, 2026 42:39


Welcome in! You've entered, Only Malware in the Building. Join us each month to sip tea and solve mysteries about today's most interesting threats. Your host is ⁠⁠⁠⁠⁠⁠⁠⁠Selena Larson⁠⁠⁠⁠⁠⁠⁠⁠, ⁠⁠⁠⁠⁠⁠⁠⁠Proofpoint⁠⁠⁠⁠⁠⁠⁠⁠ intelligence analyst and host of their podcast ⁠⁠⁠⁠⁠⁠⁠⁠DISCARDED⁠⁠⁠⁠⁠⁠⁠⁠. Inspired by the residents of a building in New York's exclusive upper west side, Selena is joined by her co-hosts ⁠⁠⁠⁠⁠⁠⁠⁠N2K Networks⁠⁠⁠⁠⁠⁠⁠⁠ ⁠⁠⁠⁠⁠⁠⁠⁠Dave Bittner⁠⁠⁠⁠⁠⁠⁠⁠ and ⁠⁠⁠⁠⁠⁠⁠Keith Mularski⁠⁠⁠⁠⁠⁠⁠, former FBI cybercrime investigator and now Chief Global Ambassador at ⁠⁠⁠⁠⁠⁠⁠Qintel⁠⁠⁠⁠⁠⁠⁠. Being a security researcher is a bit like being a detective: you gather clues, analyze the evidence, and consult the experts to solve the cyber puzzle. On this episode, we discuss findings from the Sophos Active Adversary Report 2026 by Sophos, highlighting how identity-related weaknesses like compromised credentials and gaps in MFA continue to drive a majority of security incidents. The conversation explores how attackers are moving faster, often operating after hours, and how a growing number of threat groups is adding to the complexity.

Cyber Security Today
Russian State Hackers Go After IoS Devices

Cyber Security Today

Play Episode Listen Later Mar 30, 2026 19:42


Mac Malware 'Infinity Stealer,' DarkSword iOS Exploits, China Telecom Espionage & TeamTNT Supply Chain Hits Cybersecurity Today would like to thank Meter for their support in bringing you this podcast. Meter delivers a complete networking stack, wired, wireless and cellular in one integrated solution that's built for performance and scale. You can find them at Meter.com/cst David Shipley reports from Seoul on major threats: Malwarebytes details Infinity Stealer, a new macOS info-stealer delivered via "ClickFix" social engineering and built as a compiled Python payload (Nuitka) that steals browser credentials, Keychain data, crypto wallets, and developer secrets while notifying attackers via Telegram. Proofpoint links Russia-aligned TA446 (Cold River/Star Blizzard) to spear-phishing using the DarkSword iOS exploit kit to deliver GhostBlade, with DarkSword now leaked on GitHub and Apple pushing unusual on-device warnings for vulnerable iOS versions. Rapid7 describes China-linked "Red Menshen" using the kernel-level BPFdoor backdoor to persist in global telecom networks. TeamTNT compromises the Telnyx PyPI package with WAV-steganography payloads that steal secrets and target Kubernetes. Iran-linked activity includes a symbolic FBI director email breach and escalating, deliberate healthcare disruption via attacks on Stryker and a Pay2Key incident. 00:00 Show Intro and Sponsor 00:53 Mac ClickFix Stealer 03:25 Dark Sword iOS Exploits 06:30 China Telecom Backdoor 08:47 TeamTNT PyPI Supply Chain 12:20 Iran Cyber and Healthcare 17:41 Wrap Up and Thanks 18:43 Sponsor Message

The Segment: A Zero Trust Leadership Podcast
How Cybercriminals Manipulate Trust — Then Steal Millions | Timothy Kromphardt

The Segment: A Zero Trust Leadership Podcast

Play Episode Listen Later Mar 25, 2026 39:02


Social engineering attacks may evolve with new technology, but the core tactic hasn't changed in decades: exploiting human trust. In this episode of The Segment, host Raghu Nandakumara sits down with Timothy Kromphardt, Senior Threat Researcher at Proofpoint to explore how modern scams actually work behind the scenes. Tim spends his days engaging directly with threat actors—sometimes for months at a time—to understand how fraud campaigns operate, how scammers build trust, and how they ultimately convince victims to hand over money or sensitive information. Together, they unpack the mechanics of today's most common scams, including TOAD (telephone-oriented attack delivery) attacks, business email compromise, and the increasingly sophisticated “pig butchering” investment scams that can drain victims' life savings after months of relationship-building. Together, Raghu and Tim unpack: Why social engineering continues to succeed—even as security technology improves   How pig butchering scams build trust over months before stealing massive sums   What happens when researchers directly engage with scammers   Why AI is helping attackers scale operations—but not necessarily replace humans   Practical steps organizations and individuals can take to reduce their risk   If you've ever wondered how scammers actually operate—or why even highly successful professionals sometimes fall victim—this episode offers a rare inside look at the human side of cybercrime.   Stay Connected with our host, Raghu on LinkedIn For more information about Illumio, check out our website at illumio.com 

Born In Silicon Valley
AI Will Break Email

Born In Silicon Valley

Play Episode Listen Later Mar 3, 2026 35:12


The AI revolution isn't coming—it's already here, and it's systematically breaking legacy email security as we know it. In this episode of Born in Silicon Valley, Alan LeFort, Co-Founder and CEO of StrongestLayer, reveals exactly why pattern-matching defenses are failing against AI-generated attacks and how his team is engineering reasoning-based detection to secure the future of enterprise communication. Alan brings over 25 years of experience scaling products at tech giants like Proofpoint, McAfee, and Intel. We dive into the critical pivot from large corporate life to startup innovation, exploring why true disruption requires a 10X leap in performance, not just incremental improvement. We also unpack the reality of the cybersecurity landscape: what hackers are really after, why AI is the ultimate double-edged sword, and how StrongestLayer is building the third generation of email security specifically for the AI era. Chapters 00:00 Introduction to Alan LeFort and StrongLayer 03:01 Alan's Unique Career Journey 06:13 The Decision to Join a Startup 07:52 The Role of Age in Startup Leadership 09:44 AI's Impact on Business and Email Security 13:12 The Challenges of Email Security 16:10 Disrupting Existing Categories in Sales 19:29 Key Metrics for Email Security Success 19:55 Common Threats in Email Security 21:57 Advice for Employees on Email Security 24:47 AI and Data Privacy in Security 27:32 StrongLayer's Growth and Future Plans 29:30 Navigating Change Management in Growth 32:31 The Future of Email Security 35:38 Dealing with Ransomware and Cyber Threats 38:12 Preparing for AI-Driven Attacks 39:34 Building a Strong Team for Growth 43:55 Identifying Key Roles for Success Host: Jake Aaron Villarreal leads the top AI recruitment firm in Silicon Valley, www.matchrelevant.com, uncovering stories of funded startups and going behind the scenes to tell their founders' journeys. If you are growing an AI startup or have a great story to tell, email us at: jake.villarreal@matchrelevant.com

Risky Business
Risky Business #825 -- Palo Alto Networks blames it on the boogie

Risky Business

Play Episode Listen Later Feb 18, 2026 63:13


On this week's show, Patrick Gray, Adam Boileau and James WIlson discuss the week's cybersecurity news. They cover: Palo Alto threat researchers want to attribute to China, but management says shush An increasing proportion of ransomware is data extortion. Is this good? Cambodia says it's going to dismantle scam compounds CISA sufferers through yet another shutdown Google Gemini's training secrets are being systematically harvested to improve other LLMs Academics assess SaaS password managers' resilience against a malicious server This episode is sponsored by SSO-firewall integration vendor Knocknoc. Chief exec Adam Pointon joins to talk about the latest in defences… which is to say Knocknoc for Solaris/Sparc and HPUX on PA-RISC?! Okay also that other little known OS… Windows. This episode is also available on Youtube. Show notes Data-only extortion grows as ransomware gangs seek better profits | Cybersecurity Dive Arctic Wolf Threat Report 2026 Exclusive: Palo Alto chose not to tie China to hacking campaign for fear of retaliation from Beijing, sources say Risky Bulletin: Cambodia promises to dismantle scam networks by April - Risky Business Media Age of the ‘scam state': how an illicit, multibillion-dollar industry has taken root in south-east Asia | Cybercrime | The Guardian Critical flaw in BeyondTrust Remote Support sees early signs of exploitation | Cybersecurity Dive CISA Navigates DHS Shutdown With Reduced Staff - SecurityWeek Kimwolf Botnet Swamps Anonymity Network I2P – Krebs on Security BADIIS to the Bone: New Insights to a Global SEO Poisoning Campaign — Elastic Security Labs Over 500,000 VKontakte accounts hijacked through malicious Chrome extensions | The Record from Recorded Future News Password managers' promise that they can't see your vaults isn't always true - Ars Technica Zero Knowledge (About) Encryption: A Comparative Security Analysis of Three Cloud-based Password Managers Google finds state-sponsored hackers use AI at 'all stages' of attack cycle | CyberScoop Google: Gemini hit with 100,000+ prompts in cloning attempt Proofpoint acquires Acuvity to tackle the security risks of agentic AI | CyberScoop Cisco Redefines Security for the Agentic Era with AI Defense Expansion and AI-Aware SASE Sophos Acquires Arco Cyber to Bring CISO-Level, Agentic AI-Powered Expertise to Every Organization Dave Kennedy on X: "Regarding this, there was a couple questions on does the pacemaker continue to advertise - most BLE implantable devices go into a sleep type mode. In this case, we are lucky - it does not. We know based on law enforcement answers that she is using a more modern pacemaker with" / X Clash Report on X: "BIG: Dutch Defence Minister Gijs Tuinman hints that software independence is possible for F-35 jets. He literally said you can “jailbreak” an F-35. When asked if Europe can modify it without US approval: “That's not the point… we'll see whether the Americans will show https://t.co/f11cGvtYsO" / X Dutch police arrest man who refused to delete confidential files shared by mistake | The Record from Recorded Future News

Hacking Humans
When legit is the trick: Phishing's sneaky new moves. [OMITB]

Hacking Humans

Play Episode Listen Later Feb 3, 2026 39:55


Welcome in! You've entered, Only Malware in the Building. Join us each month to sip tea and solve mysteries about today's most interesting threats. Your host is ⁠⁠⁠⁠⁠⁠Selena Larson⁠⁠⁠⁠⁠⁠, ⁠⁠⁠⁠⁠⁠Proofpoint⁠⁠⁠⁠⁠⁠ intelligence analyst and host of their podcast ⁠⁠⁠⁠⁠⁠DISCARDED⁠⁠⁠⁠⁠⁠. Inspired by the residents of a building in New York's exclusive upper west side, Selena is joined by her co-hosts ⁠⁠⁠⁠⁠⁠N2K Networks⁠⁠⁠⁠⁠⁠ ⁠⁠⁠⁠⁠⁠Dave Bittner⁠⁠⁠⁠⁠⁠ and ⁠⁠⁠⁠⁠Keith Mularski⁠⁠⁠⁠⁠, former FBI cybercrime investigator and now Chief Global Ambassador at ⁠⁠⁠⁠⁠Qintel⁠⁠⁠⁠⁠. Being a security researcher is a bit like being a detective: you gather clues, analyze the evidence, and consult the experts to solve the cyber puzzle. On this episode, our hosts discuss how attackers are increasingly abusing legitimate, trusted Microsoft workflows to make phishing campaigns more convincing and harder to spot. In device code phishing, victims are socially engineered into completing a real Microsoft OAuth login flow, inadvertently granting attackers valid access tokens without ever sharing a password. They also examined abuse of Microsoft 365 Direct Send, which allows threat actors to send phishing emails that appear to originate from inside an organization, reinforcing a broader shift toward weaponizing built-in cloud services rather than relying on obviously malicious infrastructure.

Only Malware in the Building
When legit is the trick: Phishing's sneaky new moves.

Only Malware in the Building

Play Episode Listen Later Feb 3, 2026 39:55


Welcome in! You've entered, Only Malware in the Building. Join us each month to sip tea and solve mysteries about today's most interesting threats. Your host is ⁠⁠⁠⁠⁠⁠Selena Larson⁠⁠⁠⁠⁠⁠, ⁠⁠⁠⁠⁠⁠Proofpoint⁠⁠⁠⁠⁠⁠ intelligence analyst and host of their podcast ⁠⁠⁠⁠⁠⁠DISCARDED⁠⁠⁠⁠⁠⁠. Inspired by the residents of a building in New York's exclusive upper west side, Selena is joined by her co-hosts ⁠⁠⁠⁠⁠⁠N2K Networks⁠⁠⁠⁠⁠⁠ ⁠⁠⁠⁠⁠⁠Dave Bittner⁠⁠⁠⁠⁠⁠ and ⁠⁠⁠⁠⁠Keith Mularski⁠⁠⁠⁠⁠, former FBI cybercrime investigator and now Chief Global Ambassador at ⁠⁠⁠⁠⁠Qintel⁠⁠⁠⁠⁠. Being a security researcher is a bit like being a detective: you gather clues, analyze the evidence, and consult the experts to solve the cyber puzzle. On this episode, our hosts discuss how attackers are increasingly abusing legitimate, trusted Microsoft workflows to make phishing campaigns more convincing and harder to spot. In device code phishing, victims are socially engineered into completing a real Microsoft OAuth login flow, inadvertently granting attackers valid access tokens without ever sharing a password. They also examined abuse of Microsoft 365 Direct Send, which allows threat actors to send phishing emails that appear to originate from inside an organization, reinforcing a broader shift toward weaponizing built-in cloud services rather than relying on obviously malicious infrastructure.

Hacking Humans
Poisoned at the source. [OMITB]

Hacking Humans

Play Episode Listen Later Jan 6, 2026 44:45


Welcome in! You've entered, Only Malware in the Building. Join us each month to sip tea and solve mysteries about today's most interesting threats. Your host is ⁠⁠⁠⁠⁠Selena Larson⁠⁠⁠⁠⁠, ⁠⁠⁠⁠⁠Proofpoint⁠⁠⁠⁠⁠ intelligence analyst and host of their podcast ⁠⁠⁠⁠⁠DISCARDED⁠⁠⁠⁠⁠. Inspired by the residents of a building in New York's exclusive upper west side, Selena is joined by her co-hosts ⁠⁠⁠⁠⁠N2K Networks⁠⁠⁠⁠⁠ ⁠⁠⁠⁠⁠Dave Bittner⁠⁠⁠⁠⁠ and ⁠⁠⁠⁠Keith Mularski⁠⁠⁠⁠, former FBI cybercrime investigator and now Chief Global Ambassador at ⁠⁠⁠⁠Qintel⁠⁠⁠⁠. Being a security researcher is a bit like being a detective: you gather clues, analyze the evidence, and consult the experts to solve the cyber puzzle. On this episode, we dive into supply chain attacks through the lens of a massive Android malware campaign that infects devices before they ever reach users, embedding itself in firmware and reseller-installed system images. We connect the dots to other high-impact supply chain incidents—from SolarWinds to the recent F5 breach—and share new intelligence on Android devices compromised during manufacturing and distribution in China. Together, these cases highlight how attacks at the source can quietly scale, persist, and evade traditional defenses.

Only Malware in the Building
Poisoned at the source.

Only Malware in the Building

Play Episode Listen Later Jan 6, 2026 44:45


Welcome in! You've entered, Only Malware in the Building. Join us each month to sip tea and solve mysteries about today's most interesting threats. Your host is ⁠⁠⁠⁠⁠Selena Larson⁠⁠⁠⁠⁠, ⁠⁠⁠⁠⁠Proofpoint⁠⁠⁠⁠⁠ intelligence analyst and host of their podcast ⁠⁠⁠⁠⁠DISCARDED⁠⁠⁠⁠⁠. Inspired by the residents of a building in New York's exclusive upper west side, Selena is joined by her co-hosts ⁠⁠⁠⁠⁠N2K Networks⁠⁠⁠⁠⁠ ⁠⁠⁠⁠⁠Dave Bittner⁠⁠⁠⁠⁠ and ⁠⁠⁠⁠Keith Mularski⁠⁠⁠⁠, former FBI cybercrime investigator and now Chief Global Ambassador at ⁠⁠⁠⁠Qintel⁠⁠⁠⁠. Being a security researcher is a bit like being a detective: you gather clues, analyze the evidence, and consult the experts to solve the cyber puzzle. On this episode, we dive into supply chain attacks through the lens of a massive Android malware campaign that infects devices before they ever reach users, embedding itself in firmware and reseller-installed system images. We connect the dots to other high-impact supply chain incidents—from SolarWinds to the recent F5 breach—and share new intelligence on Android devices compromised during manufacturing and distribution in China. Together, these cases highlight how attacks at the source can quietly scale, persist, and evade traditional defenses.

The CyberWire
Don't trust that app!

The CyberWire

Play Episode Listen Later Jan 3, 2026 20:41


While our team is out on winter break, please enjoy this episode of Research Saturday. Today we are joined by ⁠⁠Selena Larson⁠⁠, co-host of ⁠⁠Only Malware in the Building⁠⁠ and Staff Threat Researcher and Lead Intelligence Analysis and Strategy at ⁠⁠Proofpoint⁠⁠, sharing their work on "Microsoft OAuth App Impersonation Campaign Leads to MFA Phishing." Proofpoint researchers have identified campaigns where threat actors use fake Microsoft OAuth apps to impersonate services like Adobe, DocuSign, and SharePoint, stealing credentials and bypassing MFA via attacker-in-the-middle phishing kits, mainly Tycoon. These attacks redirect users to fake Microsoft login pages to capture credentials, 2FA tokens, and session cookies, targeting nearly 3,000 Microsoft 365 accounts across 900 environments in 2025. Microsoft's upcoming security changes and strengthened email, cloud, and web defenses, along with user education, are recommended to reduce these risks. The research can be found here: ⁠⁠⁠⁠Microsoft OAuth App Impersonation Campaign Leads to MFA Phishing Learn more about your ad choices. Visit megaphone.fm/adchoices

Research Saturday
Don't trust that app!

Research Saturday

Play Episode Listen Later Jan 3, 2026 20:41


While our team is out on winter break, please enjoy this episode of Research Saturday. Today we are joined by ⁠⁠Selena Larson⁠⁠, co-host of ⁠⁠Only Malware in the Building⁠⁠ and Staff Threat Researcher and Lead Intelligence Analysis and Strategy at ⁠⁠Proofpoint⁠⁠, sharing their work on "Microsoft OAuth App Impersonation Campaign Leads to MFA Phishing." Proofpoint researchers have identified campaigns where threat actors use fake Microsoft OAuth apps to impersonate services like Adobe, DocuSign, and SharePoint, stealing credentials and bypassing MFA via attacker-in-the-middle phishing kits, mainly Tycoon. These attacks redirect users to fake Microsoft login pages to capture credentials, 2FA tokens, and session cookies, targeting nearly 3,000 Microsoft 365 accounts across 900 environments in 2025. Microsoft's upcoming security changes and strengthened email, cloud, and web defenses, along with user education, are recommended to reduce these risks. The research can be found here: ⁠⁠⁠⁠Microsoft OAuth App Impersonation Campaign Leads to MFA Phishing Learn more about your ad choices. Visit megaphone.fm/adchoices

Hacking Humans
Hot sauce and hot takes: An Only Malware in the Building special.

Hacking Humans

Play Episode Listen Later Jan 1, 2026 36:37


While our team is out on winter break, please enjoy this episode of Only Malware in the Building. Welcome in! You've entered, Only Malware in the Building — but this time, it's not just another episode. This is a special edition you won't want to miss. For the first time, our hosts are together in-studio — and they're turning up the heat. Literally. Join ⁠⁠⁠⁠⁠⁠Selena Larson⁠⁠⁠⁠⁠⁠, ⁠⁠⁠⁠⁠⁠Proofpoint⁠⁠⁠⁠⁠⁠ intelligence analyst and host of their podcast ⁠⁠⁠⁠⁠⁠DISCARDED⁠, along with  ⁠⁠⁠⁠⁠⁠N2K Networks⁠⁠⁠⁠⁠⁠ ⁠⁠⁠⁠⁠⁠Dave Bittner⁠⁠⁠⁠⁠⁠ and ⁠⁠⁠⁠⁠Keith Mularski⁠⁠⁠⁠⁠, former FBI cybercrime investigator and now Chief Global Ambassador at ⁠⁠⁠⁠⁠Qintel⁠⁠⁠⁠⁠⁠⁠⁠⁠, as they take on a fiery hot wings challenge while answering personal questions about themselves, their careers, and the stories that shaped them. Think you've seen them tackle malware mysteries before? Wait until you see them sweat. This one's too good for audio alone — you'll want to watch the full ⁠video⁠ edition to catch every spicy reaction, every laugh, and maybe even a few tears. So grab your milk, get ready to feel the burn, and come join us for this special hot take on Only Malware in the Building.

The CyberWire
Yippee-ki-yay, cybercriminals! [OMITB]

The CyberWire

Play Episode Listen Later Dec 25, 2025 40:18


While our team is out on winter break, please enjoy this episode of Only Malware in the Building. Welcome in! You've entered, Only Malware in the Building. Wrap yourself in a warm blanket, pour your favorite mug of tea, and join us each month as we unwrap the season's juiciest cyber mysteries. Your host is ⁠⁠⁠⁠⁠⁠Selena Larson⁠⁠⁠⁠⁠⁠, ⁠⁠⁠⁠⁠⁠Proofpoint⁠⁠⁠⁠⁠⁠ intelligence analyst and host of their podcast ⁠⁠⁠⁠⁠⁠DISCARDED⁠⁠⁠⁠⁠⁠. Inspired by the residents of a building in New York's exclusive upper west side, Selena is joined by her co-hosts ⁠⁠⁠⁠⁠⁠N2K Networks⁠⁠⁠⁠⁠⁠ ⁠⁠⁠⁠⁠⁠Dave Bittner⁠⁠⁠⁠⁠⁠ and ⁠⁠⁠⁠⁠Keith Mularski⁠⁠⁠⁠⁠, former FBI cybercrime investigator and now Chief Global Ambassador at ⁠⁠⁠⁠⁠Qintel⁠⁠⁠⁠⁠. Being a security researcher is a bit like being a detective: you gather clues, analyze the evidence, and consult the experts to solve the cyber puzzle. On this episode, we explore Remote access, real cargo: cybercriminals targeting trucking and logistics. From clever schemes to protect shipments to the tools cybercriminals use, our guests discuss how organizations can safeguard physical goods in an increasingly connected world—because even during the season of hustle and bustle, the threats don't take a holiday. Learn more about your ad choices. Visit megaphone.fm/adchoices

The Cybersecurity Defenders Podcast
#275 - Defender Fridays: Polymorphic Panic - Debunking the AI Malware Myth with Randy Pargman from Proofpoint

The Cybersecurity Defenders Podcast

Play Episode Listen Later Dec 12, 2025 32:35


Join us for this week's Defender Fridays as we explore the reality of AI-powered malware threats with Randy Pargman, Senior Director of Threat Detection at Proofpoint.At Defender Fridays, we delve into the dynamic world of information security, exploring its defensive side with seasoned professionals from across the industry. Our aim is simple yet ambitious: to foster a collaborative space where ideas flow freely, experiences are shared, and knowledge expands.In this episode, Randy challenges the hype around AI-powered polymorphic malware and examines how threat actors actually operate in practice. He discusses why defenders should focus on real-world threats rather than theoretical sophisticated attacks.Key Topics:The gap between AI malware hype and practical realityWhy threat actors prefer simple, effective methods over sophisticated techniquesThe prevalence of legitimate RMM tools in modern attacksBuilding practical detection strategies for actual threatsLessons from physical security that apply to cybersecurity defenseRandy Pargman is Senior Director of Threat Detection at Proofpoint, where he leads detection engineering, sandbox development, and threat actor tracking initiatives. Join us every Friday at 10:30am PT for live, interactive discussions with industry experts. Whether you're a seasoned professional or just curious about the field, these sessions offer an engaging dialogue between our guests, hosts, and you – our audience. Register here: https://limacharlie.io/defender-fridaysSubscribe to our YouTube channel and hit the notification bell to never miss a live session or catch up on past episodes on our website!This episode is brought to you by LimaCharlie, the world's first SecOps Cloud Platform (SCP). Build and customize your security stack like "lego blocks" with our flexible, API-first solution.Eliminate vendor sprawl and tool complexityDeploy and scale effortlessly on native multi-tenant architectureReduce costs with intelligent data routing and free 1-year retentionBuild custom solutions with 100+ security capabilities on-demandImprove response times with automation and real-time capabilitiesTry the SecOps Cloud Platform free: https://limacharlie.ioHost: Maxime Lamothe-Brassard - Founder at LimaCharlie

Hacking Humans
Yippee-ki-yay, cybercriminals! [OMITB]

Hacking Humans

Play Episode Listen Later Dec 2, 2025 40:18


Welcome in! You've entered, Only Malware in the Building. Wrap yourself in a warm blanket, pour your favorite mug of tea, and join us each month as we unwrap the season's juiciest cyber mysteries. Your host is ⁠⁠⁠⁠⁠Selena Larson⁠⁠⁠⁠⁠, ⁠⁠⁠⁠⁠Proofpoint⁠⁠⁠⁠⁠ intelligence analyst and host of their podcast ⁠⁠⁠⁠⁠DISCARDED⁠⁠⁠⁠⁠. Inspired by the residents of a building in New York's exclusive upper west side, Selena is joined by her co-hosts ⁠⁠⁠⁠⁠N2K Networks⁠⁠⁠⁠⁠ ⁠⁠⁠⁠⁠Dave Bittner⁠⁠⁠⁠⁠ and ⁠⁠⁠⁠Keith Mularski⁠⁠⁠⁠, former FBI cybercrime investigator and now Chief Global Ambassador at ⁠⁠⁠⁠Qintel⁠⁠⁠⁠. Being a security researcher is a bit like being a detective: you gather clues, analyze the evidence, and consult the experts to solve the cyber puzzle. On this episode, we explore Remote access, real cargo: cybercriminals targeting trucking and logistics. From clever schemes to protect shipments to the tools cybercriminals use, our guests discuss how organizations can safeguard physical goods in an increasingly connected world—because even during the season of hustle and bustle, the threats don't take a holiday.

The CyberWire
Pass the intel, please. [Only Malware in the Building]

The CyberWire

Play Episode Listen Later Nov 28, 2025 38:06


Please enjoy this encore of Only Malware in the Building. Welcome in! You've entered, Only Malware in the Building. Join us each month to sip tea and solve mysteries about today's most interesting threats. Your host is ⁠⁠⁠⁠⁠Selena Larson⁠⁠⁠⁠⁠, ⁠⁠⁠⁠⁠Proofpoint⁠⁠⁠⁠⁠ intelligence analyst and host of their podcast ⁠⁠⁠⁠⁠DISCARDED⁠⁠⁠⁠⁠. Inspired by the residents of a building in New York's exclusive upper west side, Selena is joined by her co-hosts ⁠⁠⁠⁠⁠N2K Networks⁠⁠⁠⁠⁠ ⁠⁠⁠⁠⁠Dave Bittner⁠⁠⁠⁠⁠ and ⁠⁠⁠⁠Keith Mularski⁠⁠⁠⁠, former FBI cybercrime investigator and now Chief Global Ambassador at ⁠⁠⁠⁠Qintel⁠⁠⁠⁠. Being a security researcher is a bit like being a detective: you gather clues, analyze the evidence, and consult the experts to solve the cyber puzzle. On this episode, we explore what makes information sharing actually work. From public-private partnerships to actionable intelligence, our guests discuss how organizations can prioritize, process, and operationalize shared cyber threat data to stay ahead of emerging risks. Plus, catch Dave, Selena, and Keith on their road trip adventure in our video on ⁠⁠YouTube⁠⁠ — full of laughs, unexpected detours, and plenty of sleuthing! Learn more about your ad choices. Visit megaphone.fm/adchoices

Brave Women at Work
Yours for the Taking: Charting Your Path to the Top with Tracey Newell

Brave Women at Work

Play Episode Listen Later Nov 20, 2025 52:11


Today, I had the privilege of having Tracey Newell on as a guest. We chatted about more women making their way to the top, no matter what the level means to you. Listen in to be inspired and challenged to reach your next level.Here's more about Tracey:Tracey Newell is the former president of Informatica, where she also served as a member of the company's board of directors for two years prior to being asked to join the management team. Prior to joining Informatica, Newell served as executive vice president of global field operations at Proofpoint, where she led sales through a five-year period of hypergrowth. Recognized as a Top 100 Sales Leader by The Modern Sale, Newell led Proofpoint's go-to-market team to become a top five leader in the cybersecurity market. Newell has also served as executive vice president of global sales at Polycom and held sales leadership positions at Juniper Networks, Webex, and Cisco Systems.Newell currently serves in the non-profit organization Impact 100, and is also a member of the board of advisors for the University of California, Santa Barbara's economics department. In addition to Druva, Newell serves on the board of directors of DataRobot, Highspot, Sailpoint, and Sumo Logic. Before we begin, if the Brave Women at Work Podcast has helped you personally or professionally, please share it with a friend, colleague, or family member. And your ratings and reviews help the show continue to gain traction and grow. Thank you again!Also, a Brave Women at Work Affirmation Deck is available in time for the holidays! It is a 54-card deck that is a beautiful compilation of advice and hard-won wisdom from podcast guests, Brave Women at Work Podcast guests, authors in the anthology series, and community members! You can grab a copy of the deck for $19.99 plus $10 shipping. To purchase your deck, visit Brave Women at Work and click on Resources. From there, you will see the Affirmation Cards page. I hope you enjoy them!

Hacking Humans
Pass the intel, please. [OMITB]

Hacking Humans

Play Episode Listen Later Nov 4, 2025 38:06


Welcome in! You've entered, Only Malware in the Building. Join us each month to sip tea and solve mysteries about today's most interesting threats. Your host is ⁠⁠⁠⁠Selena Larson⁠⁠⁠⁠, ⁠⁠⁠⁠Proofpoint⁠⁠⁠⁠ intelligence analyst and host of their podcast ⁠⁠⁠⁠DISCARDED⁠⁠⁠⁠. Inspired by the residents of a building in New York's exclusive upper west side, Selena is joined by her co-hosts ⁠⁠⁠⁠N2K Networks⁠⁠⁠⁠ ⁠⁠⁠⁠Dave Bittner⁠⁠⁠⁠ and ⁠⁠⁠Keith Mularski⁠⁠⁠, former FBI cybercrime investigator and now Chief Global Ambassador at ⁠⁠⁠Qintel⁠⁠⁠. Being a security researcher is a bit like being a detective: you gather clues, analyze the evidence, and consult the experts to solve the cyber puzzle. On this episode, we explore what makes information sharing actually work. From public-private partnerships to actionable intelligence, our guests discuss how organizations can prioritize, process, and operationalize shared cyber threat data to stay ahead of emerging risks. Plus, catch Dave, Selena, and Keith on their road trip adventure in our video on ⁠YouTube⁠ — full of laughs, unexpected detours, and plenty of sleuthing!

The Agile World with Greg Kihlstrom
#742: Making frictionless payments a reality with Peter Galvin, NMI

The Agile World with Greg Kihlstrom

Play Episode Listen Later Sep 29, 2025 28:16


How do we future-proof the digital payment experience so it becomes invisible to customers—yet keep it working harder than ever for brands?Agility requires a deep understanding of how technology can simplify the customer journey without compromising security or trust.Today we're going to talk about the future of secure digital payments, how in-app and frictionless experiences are redefining customer loyalty, and why platform providers need to take the in-app payment shift seriously.To help me discuss this topic, I'd like to welcome Peter Galvin, Chief Marketing Officer at NMI. About Peter Galvin Peter is Chief Marketing Officer at NMI and is a 20-year veteran of global technology organizations, specializing in promoting innovative enterprise and Cloud-based software companies to leadership positions. He previously served as Chief Marketing Officer at Entrust and Proofpoint, as well as Chief Strategy & Marketing Officer for nCipher (formerly Thales e-Security). Peter has also served in senior marketing leadership roles at leading technology companies including Openwave, Inktomi (acquired by Yahoo) and Oracle. He's passionate about skiing and travel, and enjoys cooking and spending time with his family. Peter Galvin on LinkedIn: https://www.linkedin.com/in/petergalvin/ Resources NMI: https://www.nmi.com The Agile Brand podcast is brought to you by TEKsystems. Learn more here: https://www.teksystems.com/versionnextnow Register now for Sitecore Symposium, November 3-5 in Orlando Florida. Use code SYM25-2Media10 to receive 10% off. Go here for more: https://symposium.sitecore.com/Don't Miss MAICON 2025, October 14-16 in Cleveland - the event bringing together the brights minds and leading voices in AI. Use Code AGILE150 for $150 off registration. Go here to register: https://bit.ly/agile150 Connect with Greg on LinkedIn: https://www.linkedin.com/in/gregkihlstromDon't miss a thing: get the latest episodes, sign up for our newsletter and more: https://www.theagilebrand.showCheck out The Agile Brand Guide website with articles, insights, and Martechipedia, the wiki for marketing technology: https://www.agilebrandguide.com The Agile Brand is produced by Missing Link—a Latina-owned strategy-driven, creatively fueled production co-op. From ideation to creation, they craft human connections through intelligent, engaging and informative content. https://www.missinglink.company Hosted on Acast. See acast.com/privacy for more information.

The Agile World with Greg Kihlstrom
#742: Making frictionless payments a reality with Peter Galvin, NMI

The Agile World with Greg Kihlstrom

Play Episode Listen Later Sep 29, 2025 30:46


How do we future-proof the digital payment experience so it becomes invisible to customers—yet keep it working harder than ever for brands?Agility requires a deep understanding of how technology can simplify the customer journey without compromising security or trust. Today we're going to talk about the future of secure digital payments, how in-app and frictionless experiences are redefining customer loyalty, and why platform providers need to take the in-app payment shift seriously.To help me discuss this topic, I'd like to welcome Peter Galvin, Chief Marketing Officer at NMI. About Peter Galvin Peter is Chief Marketing Officer at NMI and is a 20-year veteran of global technology organizations, specializing in promoting innovative enterprise and Cloud-based software companies to leadership positions. He previously served as Chief Marketing Officer at Entrust and Proofpoint, as well as Chief Strategy & Marketing Officer for nCipher (formerly Thales e-Security). Peter has also served in senior marketing leadership roles at leading technology companies including Openwave, Inktomi (acquired by Yahoo) and Oracle. He's passionate about skiing and travel, and enjoys cooking and spending time with his family. Peter Galvin on LinkedIn: https://www.linkedin.com/in/petergalvin/ Resources NMI: https://www.nmi.com The Agile Brand podcast is brought to you by TEKsystems. Learn more here: https://www.teksystems.com/versionnextnow Register now for Sitecore Symposium, November 3-5 in Orlando Florida. Use code SYM25-2Media10 to receive 10% off. Go here for more: https://symposium.sitecore.com/Don't Miss MAICON 2025, October 14-16 in Cleveland - the event bringing together the brights minds and leading voices in AI. Use Code AGILE150 for $150 off registration. Go here to register: https://bit.ly/agile150 Connect with Greg on LinkedIn: https://www.linkedin.com/in/gregkihlstromDon't miss a thing: get the latest episodes, sign up for our newsletter and more: https://www.theagilebrand.showCheck out The Agile Brand Guide website with articles, insights, and Martechipedia, the wiki for marketing technology: https://www.agilebrandguide.com The Agile Brand is produced by Missing Link—a Latina-owned strategy-driven, creatively fueled production co-op. From ideation to creation, they craft human connections through intelligent, engaging and informative content. https://www.missinglink.company

The CyberWire
Don't trust that app! [Research Saturday]

The CyberWire

Play Episode Listen Later Sep 6, 2025 20:41


Today we are joined by Selena Larson, co-host of Only Malware in the Building and Staff Threat Researcher and Lead Intelligence Analysis and Strategy at Proofpoint, sharing their work on "Microsoft OAuth App Impersonation Campaign Leads to MFA Phishing." Proofpoint researchers have identified campaigns where threat actors use fake Microsoft OAuth apps to impersonate services like Adobe, DocuSign, and SharePoint, stealing credentials and bypassing MFA via attacker-in-the-middle phishing kits, mainly Tycoon. These attacks redirect users to fake Microsoft login pages to capture credentials, 2FA tokens, and session cookies, targeting nearly 3,000 Microsoft 365 accounts across 900 environments in 2025. Microsoft's upcoming security changes and strengthened email, cloud, and web defenses, along with user education, are recommended to reduce these risks. The research can be found here: ⁠Microsoft OAuth App Impersonation Campaign Leads to MFA Phishing Learn more about your ad choices. Visit megaphone.fm/adchoices

The CyberWire
Hot sauce and hot takes: An Only Malware in the Building special. [OMITB]

The CyberWire

Play Episode Listen Later Sep 2, 2025 36:37


Welcome in! You've entered, Only Malware in the Building — but this time, it's not just another episode. This is a special edition you won't want to miss. For the first time, our hosts are together in-studio — and they're turning up the heat. Literally. Join ⁠⁠⁠⁠⁠⁠Selena Larson⁠⁠⁠⁠⁠⁠, ⁠⁠⁠⁠⁠⁠Proofpoint⁠⁠⁠⁠⁠⁠ intelligence analyst and host of their podcast ⁠⁠⁠⁠⁠⁠DISCARDED⁠, along with ⁠⁠⁠⁠⁠⁠N2K Networks⁠⁠⁠⁠⁠⁠ ⁠⁠⁠⁠⁠⁠Dave Bittner⁠⁠⁠⁠⁠⁠ and ⁠⁠⁠⁠⁠Keith Mularski⁠⁠⁠⁠⁠, former FBI cybercrime investigator and now Chief Global Ambassador at ⁠⁠⁠⁠⁠Qintel⁠⁠⁠⁠⁠⁠⁠⁠⁠, as they take on a fiery hot wings challenge while answering personal questions about themselves, their careers, and the stories that shaped them. Think you've seen them tackle malware mysteries before? Wait until you see them sweat. This one's too good for audio alone — you'll want to watch the full ⁠video⁠ edition to catch every spicy reaction, every laugh, and maybe even a few tears. So grab your milk, get ready to feel the burn, and come join us for this special hot take on Only Malware in the Building. Learn more about your ad choices. Visit megaphone.fm/adchoices

Hacking Humans
Hot sauce and hot takes: An Only Malware in the Building special. [OMITB]

Hacking Humans

Play Episode Listen Later Sep 2, 2025 36:37


Welcome in! You've entered, Only Malware in the Building — but this time, it's not just another episode. This is a special edition you won't want to miss. For the first time, our hosts are together in-studio — and they're turning up the heat. Literally. Join ⁠⁠⁠⁠⁠⁠Selena Larson⁠⁠⁠⁠⁠⁠, ⁠⁠⁠⁠⁠⁠Proofpoint⁠⁠⁠⁠⁠⁠ intelligence analyst and host of their podcast ⁠⁠⁠⁠⁠⁠DISCARDED⁠, along with ⁠⁠⁠⁠⁠⁠N2K Networks⁠⁠⁠⁠⁠⁠ ⁠⁠⁠⁠⁠⁠Dave Bittner⁠⁠⁠⁠⁠⁠ and ⁠⁠⁠⁠⁠Keith Mularski⁠⁠⁠⁠⁠, former FBI cybercrime investigator and now Chief Global Ambassador at ⁠⁠⁠⁠⁠Qintel⁠⁠⁠⁠⁠⁠⁠⁠⁠, as they take on a fiery hot wings challenge while answering personal questions about themselves, their careers, and the stories that shaped them. Think you've seen them tackle malware mysteries before? Wait until you see them sweat. This one's too good for audio alone — you'll want to watch the full ⁠video⁠ edition to catch every spicy reaction, every laugh, and maybe even a few tears. So grab your milk, get ready to feel the burn, and come join us for this special hot take on Only Malware in the Building.

The CyberWire
State of emergency in St Paul.

The CyberWire

Play Episode Listen Later Jul 30, 2025 32:10


Officials in St. Paul, Minnesota declare a state of emergency following a cyberattack. Hackers disrupt a major French telecom. A power outage causes widespread service disruptions for cloud provider Linode. Researchers reveal a critical authentication bypass flaw in an AI-driven app development platform. A new study shows AI training data is chock full of PII. Fallout continues for the Tea dating safety app. Hackers are actively exploiting a critical SAP NetWeaver vulnerability to deploy malware. CISA and the FBI update their Scattered Spider advisory. A Florida prison exposes personal information of visitors to all of its inmates. Our guest today is Keith Mularski, Chief Global Ambassador at Qintel, retired FBI Special Agent, and co-host of Only Malware in the Building. CISA and Senator Wyden come to terms —mostly— over the long-buried US Telecommunications Insecurity Report.  Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Our guest today is Keith Mularski, Chief Global Ambassador at Qintel, retired FBI Special Agent, and co-host of Only Malware in the Building discussing what it's like to be the new host on the N2K CyberWire network and giving a glimpse into some upcoming episodes. You can catch Keith and his co-hosts Selena Larson, Staff Threat Researcher and Lead, Intelligence Analysis and Strategy at Proofpoint, and our own Dave Bittner the first Tuesday of each month on your favorite podcast app with new episodes of Only Malware. Selected Reading Major cyberattack hits St. Paul, shuts down many services (Star Tribune) French telecom giant Orange discloses cyberattack (Bleeping Computer) Power Outage at Newark Data Center Disrupts Linode, Took LWN Offline (FOSS Force) Critical authentication bypass flaw reported in AI coding platform Base44 (Beyond Machines) A major AI training data set contains millions of examples of personal data (MIT Technology Review) Dating safety app Tea suspends messaging after hack (BBC) Hackers exploit SAP NetWeaver bug to deploy Linux Auto-Color malware (Bleeping Computer) CISA and FBI Release Tactics, Techniques, and Procedures of the Scattered Spider Hacker Group (gb hackers) Florida prison data breach exposes visitors' contact information to inmates (Florida Phoenix) CISA to release long-buried US telco security report (The Register) Audience Survey Complete our annual audience survey before August 31. Want to hear your company in the show? You too can reach the most influential leaders and operators in the industry. Here's our media kit. Contact us at cyberwire@n2k.com to request more info. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc. Learn more about your ad choices. Visit megaphone.fm/adchoices

The CyberWire
Click here to steal. [Research Saturday]

The CyberWire

Play Episode Listen Later Jul 12, 2025 28:11


Today we are joined by ⁠Selena Larson⁠, Threat Researcher at ⁠Proofpoint⁠, and co-host of ⁠Only Malware in the Building⁠, as she discusses their work on "Amatera Stealer - Rebranded ACR Stealer With Improved Evasion, Sophistication." Proofpoint researchers have identified Amatera Stealer, a rebranded and actively developed malware-as-a-service (MaaS) variant of the former ACR Stealer, featuring advanced evasion techniques like NTSockets for stealthy C2 communication and WoW64 Syscalls to bypass user-mode defenses. Distributed via ClearFake web injects and the ClickFix technique, Amatera leverages multilayered PowerShell loaders, blockchain-based hosting, and creative social engineering to compromise victims. With enhanced capabilities to steal browser data, crypto wallets, and other sensitive files, Amatera poses a growing threat in the wake of disruptions to competing stealers like Lumma. Complete our annual ⁠audience survey⁠ before August 31. The research can be found here: ⁠Amatera Stealer: Rebranded ACR Stealer With Improved Evasion, Sophistication Learn more about your ad choices. Visit megaphone.fm/adchoices